The Passster WordPress plugin before 4.2.24 does not handle input properly in an AJAX action, allowing unauthenticated users to retrieve the value of password protected content
Metrics
Affected Vendors & Products
References
History
Mon, 07 Sep 2026 08:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Passster Project
Passster Project passster Wordpress Wordpress wordpress |
|
| Vendors & Products |
Passster Project
Passster Project passster Wordpress Wordpress wordpress |
Wed, 02 Sep 2026 16:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Wed, 02 Sep 2026 10:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | The Passster WordPress plugin before 4.2.24 does not handle input properly in an AJAX action, allowing unauthenticated users to retrieve the value of password protected content | |
| Title | Passster < 4.2.24 - Password Protection Bypass | |
| Weaknesses | CWE-863 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: WPScan
Published: 2026-09-02T14:25:48.467Z
Updated: 2026-09-02T14:57:35.985Z
Reserved: 2026-01-08T16:49:56.888Z
Link: CVE-2025-15489
Updated: 2026-09-02T14:43:09.450Z
Status : Deferred
Published: 2026-09-02T15:17:36.583
Modified: 2026-09-03T17:50:37.690
Link: CVE-2025-15489
No data.