What is CVE-2025-15674?
CVE-2025-15674 is a vulnerability in the Passster WordPress plugin before version 4.3.7 that allows low-privilege users with 'edit_posts' capability (Contributor and above) to read globally password-protected content via the WordPress core REST API. Site admins should update the plugin immediately.
Azərbaycanca: CVE-2025-15674, Passster WordPress plaginin 4.3.7-dən əvvəlki versiyalarında aşağı səlahiyyətli istifadəçilərin (Contributor və yuxarısı) qlobal parol mühafizəsi aktiv olduqda REST API vasitəsilə mühafizə olunan məzmunu oxumasına imkan verən zəiflikdir. Sayt sahibləri plagini dərhal ən son versiyaya yeniləməlidir.
Related CVEs
link basis: same weakness class CWE-862
FAQ2
Which versions of the Passster plugin are affected by CVE-2025-15674?
This vulnerability affects the Passster WordPress plugin in versions before 4.3.7.
What privilege level of users can read protected content via CVE-2025-15674?
Low-privilege users with 'edit_posts' capability (Contributor and above) can read globally password-protected content via the WordPress core REST API.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.