MEDIUM
Gutentor
CVE published 2026-09-02
CVE-2026-16983
The Gutentor WordPress plugin before 4.0.6 exposes a critical vulnerability, allowing any authenticated user with at least the Subscriber role to access plaintext passwords of password-protected posts. This is due to incorrect context restriction on one of its REST endpoints. The CVE record was published on 2026-09-02T06:17:16.547Z. Affected WordPress site administrators should review official advisories, [truncated]