Impact
The Passster WordPress plugin contains a flaw in its global protection checks. An unauthenticated attacker can craft a special URL that bypasses the protection normally applied to content. Because the flaw permits bypassing authorization checks, the attack can expose confidential data or settings that are meant to be restricted to authorized users. The weakness corresponds to CWE‑863, indicating a partial authorization bypass.
Affected Systems
WordPress sites using the Passster plugin version earlier than 4.2.26 are affected. Any installation of Passster before that release is vulnerable; no specific min/max patch level is defined beyond the 4.2.26 threshold.
Risk and Exploitability
This vulnerability has a CVSS score of 5.3, indicating moderate severity. The EPSS score is not available, and it is not listed in CISA’s KEV catalog. The attack vector is a simple crafted URL that does not require authentication, so the exploitation probability is high in environments where the plugin is deployed. Because the flaw is local to the plugin’s authorization controls, an attacker who can send arbitrary HTTP requests to the site can trigger the bypass. Organizations with sensitive or confidential content must consider this a significant risk.
OpenCVE Enrichment