CVE-2026-16983: Gutentor < 4.0.6 - Subscriber+ Password Protected Post Password Disclosure via REST API

Published Sep 2, 2026
·
Updated

The Gutentor WordPress plugin before 4.0.6 does not apply the correct context restriction to one of its REST endpoints, exposing the plaintext passwords of password-protected posts to any authenticated user with at least the Subscriber role.

Affected Software

1 affected component
Gutentor<4.0.6

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade wordpress/gutentor to a version that resolves this vulnerability.

    Fixed in 4.0.6

Event History

Sep 2, 2026
CVE Published
via MITRE·06:00 AM
Data Sourced
via MITRE·06:00 AM
DescriptionWeakness
Data Sourced
via NVD·06:17 AM
Description

Frequently Asked Questions

1

Who can exploit this issue?

Any authenticated WordPress user with at least the Subscriber role can access the affected REST endpoint. Unauthenticated visitors are not described as able to exploit it.

2

What information is exposed?

The affected endpoint can disclose plaintext passwords assigned to password-protected posts. The disclosure occurs because the endpoint does not apply the correct context restriction.

3

Which deployments are affected?

Gutentor versions before 4.0.6 are affected. The issue applies where password-protected posts exist and users can authenticate with at least a Subscriber account.

4

How can I determine whether my site may already be exposed?

Check whether Gutentor is installed at a version earlier than 4.0.6, whether the site contains password-protected posts, and whether Subscriber-or-higher accounts can authenticate. Those conditions indicate that the described exposure may be reachable.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203