What is CVE-2026-16603?
CVE-2026-16603 was found in the Passster WordPress plugin. Versions before 4.3.6 fail to enforce category-based content protection on the WordPress REST API, allowing unauthenticated users to access full content, titles, and excerpts of locked posts. The plugin must be immediately updated to the latest version.
Azərbaycanca: CVE-2026-16603, Passster WordPress plaginində aşkar edilib. 4.3.6 versiyasından əvvəlki plaginlər kateqoriya əsaslı məzmun qorunmasını WordPress REST API üzərində düzgün tətbiq etmir. Təsdiqlənməmiş istifadəçilər REST API vasitəsilə kilidlənmiş postların tam məzmununu, başlığını və qısa xülasəsini oxuya bilərlər. Plagin dərhal ən son versiyaya yenilənməlidir.
Related CVEs
link basis: same weakness class CWE-306
FAQ2
Which versions of the Passster plugin are affected by CVE-2026-16603?
All versions of the Passster plugin before 4.3.6 are affected by the vulnerability.
What data can an unauthenticated user access by exploiting CVE-2026-16603?
An unauthenticated user can access the full content, titles, and excerpts of locked posts via the REST API.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.