What is CVE-2026-16604?
This vulnerability affects the Passster WordPress plugin before version 4.3.6, where password-protected block content is exposed in the public page response before password verification, allowing unauthenticated users to access restricted content without credentials. Immediate update to the latest patched version is recommended.
Azərbaycanca: Bu boşluq Passster WordPress plugin-in 4.3.6-dan əvvəlki versiyalarına təsir edir: parolla qorunan blok məzmunu parol yoxlanılmadan səhifə cavabında açıq şəkildə ötürülür, nəticədə autentifikasiya olunmamış istifadəçilər məxfi məzmuna parolsuz giriş əldə edə bilər. Plugin-i dərhal ən son versiyaya yeniləmək tövsiyə olunur.
FAQ2
Which versions of the Passster plugin are affected by CVE-2026-16604?
This vulnerability affects the Passster WordPress plugin before version 4.3.6.
How can unauthenticated users access password-protected content via CVE-2026-16604?
Because the password-protected block content is exposed in the public page response before password verification, unauthenticated users can access restricted content without credentials.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.