CVE-2026-16603: Content Protector (Passster) < 4.3.6 - Unauthenticated Category-Locked Content Disclosure via Core REST API
Published Aug 5, 2026
·Updated
The Passster WordPress plugin before 4.3.6 does not enforce its category-based content protection on the WordPress REST API, allowing unauthenticated users to read the full content, title, and excerpt of category-locked posts through the core REST API.
Affected Software
1 affected component
Passster Content Protector (Passster)<4.3.6
Event History
Aug 5, 2026
CVE Published
via MITRE·06:00 AM
Data Sourced
via MITRE·06:00 AM
DescriptionWeakness
Data Sourced
via NVD·07:16 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2026-16603?
CVE-2026-16603 has a risk rating of 55, indicating moderate severity.
2
How do I fix CVE-2026-16603?
To address CVE-2026-16603, update the Passster plugin to version 4.3.6 or later.
3
What does CVE-2026-16603 affect?
CVE-2026-16603 affects the Passster Content Protector plugin for WordPress.
4
What type of vulnerability is CVE-2026-16603?
CVE-2026-16603 is an info leak vulnerability that allows unauthorized access to category-locked content.
5
Can unauthorized users exploit CVE-2026-16603?
Yes, CVE-2026-16603 allows unauthenticated users to access content through the WordPress REST API.