Description
The Passster WordPress plugin before 4.2.26 has a flaw in its global protection checks, allowing unauthenticated users to bypass the protection offered via crafted URLs
Published: 2026-09-02
Score: 5.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The Passster WordPress plugin contains a flaw in its global protection checks. An unauthenticated attacker can craft a special URL that bypasses the protection normally applied to content. Because the flaw permits bypassing authorization checks, the attack can expose confidential data or settings that are meant to be restricted to authorized users. The weakness corresponds to CWE‑863, indicating a partial authorization bypass.

Affected Systems

WordPress sites using the Passster plugin version earlier than 4.2.26 are affected. Any installation of Passster before that release is vulnerable; no specific min/max patch level is defined beyond the 4.2.26 threshold.

Risk and Exploitability

This vulnerability has a CVSS score of 5.3, indicating moderate severity. The EPSS score is not available, and it is not listed in CISA’s KEV catalog. The attack vector is a simple crafted URL that does not require authentication, so the exploitation probability is high in environments where the plugin is deployed. Because the flaw is local to the plugin’s authorization controls, an attacker who can send arbitrary HTTP requests to the site can trigger the bypass. Organizations with sensitive or confidential content must consider this a significant risk.

Generated by OpenCVE AI on September 3, 2026 at 11:56 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade the Passster plugin to version 4.2.26 or later, which fixes the global protection flaw.
  • If an update is not yet available, remove or deactivate the Passster plugin until the vendor releases a patched version.
  • Apply an additional site‑wide authentication layer or use a security plugin to enforce access controls on the content that was previously protected by Passster.

Generated by OpenCVE AI on September 3, 2026 at 11:56 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 03 Sep 2026 16:15:00 +0000

Type Values Removed Values Added
First Time appeared Passster Project
Passster Project passster
Wordpress
Wordpress wordpress
Vendors & Products Passster Project
Passster Project passster
Wordpress
Wordpress wordpress

Wed, 02 Sep 2026 10:45:00 +0000

Type Values Removed Values Added
Description The Passster WordPress plugin before 4.2.26 has a flaw in its global protection checks, allowing unauthenticated users to bypass the protection offered via crafted URLs
Title Passster < 4.2.26 - Global Protection Bypass
Weaknesses CWE-863
References
Metrics cvssV3_1

{'score': 5.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N'}

ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Subscriptions

Passster Project Passster
Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: WPScan

Published:

Updated: 2026-09-02T14:57:35.837Z

Reserved: 2026-01-08T17:16:19.676Z

Link: CVE-2025-15490

cve-icon Vulnrichment

Updated: 2026-09-02T14:43:05.008Z

cve-icon NVD

Status : Deferred

Published: 2026-09-02T15:17:36.713

Modified: 2026-09-03T17:50:37.690

Link: CVE-2025-15490

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-03T16:00:07Z

Weaknesses