PatchSiren

Passster CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

MEDIUM Passster CVE published 2026-09-02

CVE-2025-15490

The Passster WordPress plugin before 4.2.26 has a flaw in its global protection checks, allowing unauthenticated users to bypass the protection offered via crafted URLs. This vulnerability affects WordPress installations with the Passster plugin, potentially exposing them to unauthorized access. Administrators and security teams should assess the exposure of their Passster WordPress plugin instances and p [truncated]

MEDIUM Passster CVE published 2026-09-02

CVE-2025-15489

The Passster WordPress plugin before 4.2.24 does not handle input properly in an AJAX action, allowing unauthenticated users to retrieve the value of password protected content. This vulnerability affects WordPress administrators and security teams using Passster plugin versions before 4.2.24, who should assess exposure and prioritize upgrading to version 4.2.24 or later. The vulnerability class is relate [truncated]

MEDIUM Passster CVE published 2026-08-21

CVE-2026-17559

The Passster WordPress plugin before 4.3.9 has a vulnerability that allows an unauthenticated attacker to read the content of globally password-protected posts and pages. This is due to improper path matching in the plugin's public endpoint paths, which can be exploited by sending crafted REST API requests. Users of the Passster WordPress plugin, especially those with globally password-protected content, [truncated]

LOW Passster CVE published 2026-08-06

CVE-2025-15674

The Passster WordPress plugin before 4.3.7 does not restrict low-privilege users holding the edit_posts capability from reading globally password-protected content through the WordPress core REST API when global protection is enabled. This vulnerability allows any Contributor or higher to read the content of protected pages and posts without knowing the password. Users of the Passster WordPress plugin, pa [truncated]

HIGH Passster CVE published 2026-08-05

CVE-2026-16602

The Passster WordPress plugin before 4.3.6 does not perform a post-status check before returning post content from an unauthenticated REST endpoint, allowing unauthenticated users to disclose the content of non-public posts on sites with a configured captcha provider. This vulnerability affects site administrators who use the Passster WordPress plugin. The vulnerability allows attackers to access sensitiv [truncated]