Description
Insertion of Sensitive Information Into Sent Data vulnerability in WP Chill Passster content-protector allows Retrieve Embedded Sensitive Data.This issue affects Passster: from n/a through <= 4.2.19.
Published: 2025-12-18
Score: 7.5 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability allows the WordPress Passster content‑protector plugin to insert sensitive information into transmitted data, enabling an attacker to retrieve embedded secrets. This flaw is classified as a Confidentiality violation (CWE‑201). An attacker can gain access to confidential data that should remain private, thereby compromising the confidentiality of the site’s content.

Affected Systems

WP Chill Passster plugin versions 4.2.19 and earlier, which are used within WordPress installations. No further version granularity is provided.

Risk and Exploitability

With a CVSS score of 7.5, the issue is considered high severity. The EPSS score of less than 1% suggests a low likelihood of exploitation in the wild, and it is not currently listed in the CISA KEV catalog. The vulnerability can be abused remotely by exploiting the plugin’s data handling functions, leading to unauthorized disclosure of sensitive information.

Generated by OpenCVE AI on April 29, 2026 at 18:51 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade the Passster plugin to a version newer than 4.2.19.
  • If an update is not available, disable or remove the Passster plugin from the WordPress site.
  • Review and audit any content that may contain sensitive data before publishing to ensure it is not being exposed through the plugin.

Generated by OpenCVE AI on April 29, 2026 at 18:51 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 20 Jan 2026 15:30:00 +0000


Tue, 20 Jan 2026 14:45:00 +0000


Fri, 19 Dec 2025 09:30:00 +0000

Type Values Removed Values Added
First Time appeared Wordpress
Wordpress wordpress
Wpchill
Wpchill passster
Vendors & Products Wordpress
Wordpress wordpress
Wpchill
Wpchill passster

Thu, 18 Dec 2025 21:15:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N'}

ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 18 Dec 2025 07:45:00 +0000

Type Values Removed Values Added
Description Insertion of Sensitive Information Into Sent Data vulnerability in WP Chill Passster content-protector allows Retrieve Embedded Sensitive Data.This issue affects Passster: from n/a through <= 4.2.19.
Title WordPress Passster plugin <= 4.2.19 - Sensitive Data Exposure vulnerability
Weaknesses CWE-201
References

Subscriptions

Wordpress Wordpress
Wpchill Passster
cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-04-29T09:51:55.890Z

Reserved: 2025-10-29T03:08:02.188Z

Link: CVE-2025-64218

cve-icon Vulnrichment

Updated: 2025-12-18T20:27:50.624Z

cve-icon NVD

Status : Deferred

Published: 2025-12-18T08:16:11.780

Modified: 2026-04-15T00:35:42.020

Link: CVE-2025-64218

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-04-29T19:00:06Z

Weaknesses