What is CVE-2026-16602?
This vulnerability affects Passster WordPress plugin versions before 4.3.6. It allows unauthenticated users to access content of non-public (draft, private, and pending) posts via a REST endpoint, but only on sites with a configured captcha provider. Users should immediately update the plugin to version 4.3.6 or higher.
Azərbaycanca: Bu boşluq Passster WordPress plaginin 4.3.6-dan əvvəlki versiyalarına təsir edir. O, autentifikasiya olunmamış REST endpoint vasitəsilə qaralama, özəl və gözləmədə olan yazıların məzmununu ifşa edir, lakin yalnız captcha provayderi konfiqurasiya edilmiş saytlarda. İstifadəçilər plagini dərhal 4.3.6 və ya daha yuxarı versiyaya yeniləməlidir.
Related CVEs
link basis: same weakness class CWE-862
FAQ1
How does the Passster plugin get affected by CVE-2026-16602?
This vulnerability exposes the content of draft, private, and pending posts through an unauthenticated REST endpoint, but only on sites with a configured captcha provider.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.