Impact
The vulnerability is a missing authorization flaw that allows users to access content that should otherwise be restricted. The weakness stemmed from incorrectly configured access control security levels, enabling the bypass of intended content protection. The flaw can be exploited to read or view protected information, potentially exposing confidential user data or sensitive material present on the site, and is classified as a CWE-862 Broken Access Control.
Affected Systems
WordPress plugin Passster developed by WP Chill (content‑protector) is affected from the earliest releases through version 4.2.25. Any site using Passster up to and including 4.2.25 is vulnerable and should be treated as impacted.
Risk and Exploitability
The CVSS score of 6.5 indicates medium severity, while the EPSS score of less than 1% indicates a low probability of exploitation at the time of analysis. The vulnerability is not listed in the CISA KEV catalog. The attack vector is inferred to be remote, via the web interface, because the flaw resides in the web‑based access control configuration of the plugin. An attacker with exposure to the site and knowledge of the configuration could craft requests to bypass access restrictions and retrieve protected content.
OpenCVE Enrichment