Impact
The vulnerability allows the WordPress Passster content‑protector plugin to insert sensitive information into transmitted data, enabling an attacker to retrieve embedded secrets. This flaw is classified as a Confidentiality violation (CWE‑201). An attacker can gain access to confidential data that should remain private, thereby compromising the confidentiality of the site’s content.
Affected Systems
WP Chill Passster plugin versions 4.2.19 and earlier, which are used within WordPress installations. No further version granularity is provided.
Risk and Exploitability
With a CVSS score of 7.5, the issue is considered high severity. The EPSS score of less than 1% suggests a low likelihood of exploitation in the wild, and it is not currently listed in the CISA KEV catalog. The vulnerability can be abused remotely by exploiting the plugin’s data handling functions, leading to unauthorized disclosure of sensitive information.
OpenCVE Enrichment