Description
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WP Chill Passster content-protector allows Stored XSS.This issue affects Passster: from n/a through <= 4.2.18.
Published: 2025-09-22
Score: 6.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability is a Stored Cross‑Site Scripting flaw that allows an attacker to inject arbitrary JavaScript into content stored by the Passster plugin. When a user views the compromised content, the injected script executes in the context of the victim’s browser, potentially enabling session hijacking, phishing, or defacement. The weakness is classified as CWE‑79, reflecting improper handling of user‑supplied input during web page generation.

Affected Systems

WordPress sites that have the Passster content‑protector plugin version 4.2.18 or earlier installed are affected. The plugin is distributed by WP Chill under the product name Passster.

Risk and Exploitability

The CVSS score of 6.5 indicates a moderate severity impact. The EPSS score of less than 1% shows a very low probability that automated attacks have been observed against this weakness. The vulnerability is not currently listed in the CISA KEV catalog, suggesting it has not yet been widely exploited in the wild. Attackers would likely inject malicious content via the plugin’s content‑editing interface, taking advantage of the stored XSS path to compromise any visitor to the infected page.

Generated by OpenCVE AI on April 30, 2026 at 06:26 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update the Passster plugin to version 4.2.19 or newer which removes the XSS flaw.
  • If an update is not immediately possible, disable the Passster plugin and remove any stored content that may contain malicious scripts.
  • Add a Content‑Security‑Policy header that disallows inline script execution to mitigate the impact of any remaining stored payload.

Generated by OpenCVE AI on April 30, 2026 at 06:26 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2025-30705 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WP Chill Passster allows Stored XSS. This issue affects Passster: from n/a through 4.2.18.
History

Thu, 23 Apr 2026 15:00:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L'}


Wed, 01 Apr 2026 23:45:00 +0000

Type Values Removed Values Added
Description Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WP Chill Passster allows Stored XSS. This issue affects Passster: from n/a through 4.2.18. Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WP Chill Passster content-protector allows Stored XSS.This issue affects Passster: from n/a through <= 4.2.18.
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L'}


Wed, 24 Sep 2025 13:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 23 Sep 2025 16:15:00 +0000

Type Values Removed Values Added
First Time appeared Wordpress
Wordpress wordpress
Wpchill
Wpchill passster
Vendors & Products Wordpress
Wordpress wordpress
Wpchill
Wpchill passster

Mon, 22 Sep 2025 18:30:00 +0000

Type Values Removed Values Added
Description Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WP Chill Passster allows Stored XSS. This issue affects Passster: from n/a through 4.2.18.
Title WordPress Passster Plugin <= 4.2.18 - Cross Site Scripting (XSS) Vulnerability
Weaknesses CWE-79
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L'}


Subscriptions

Wordpress Wordpress
Wpchill Passster
cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-05-12T00:52:22.101Z

Reserved: 2025-08-22T11:36:24.369Z

Link: CVE-2025-57926

cve-icon Vulnrichment

Updated: 2025-09-24T13:09:28.199Z

cve-icon NVD

Status : Deferred

Published: 2025-09-22T19:15:49.647

Modified: 2026-04-23T15:33:02.680

Link: CVE-2025-57926

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-04-30T06:30:29Z

Weaknesses