Impact
The vulnerability is an unauthenticated broken access control flaw in the WordPress Passster plugin up to version 4.3. bypass the plugin’s protection mechanisms and view or modify content that should be restricted, effectively gaining unauthorized read or modify privileges. It is categorized as CWE-862. The impact is confined to the sites running the vulnerable plugin and could expose confidential or restricted information stored within the WordPress installation.
Affected Systems
The WP Chill:Passster WordPress plugin is affected in all releases up to 4.3.13. Any WordPress site that has this version installed should verify the plugin version and plan to upgrade or disable the plugin if the vulnerability must be mitigated immediately.
Risk and Exploitability
The CVSS score of 5.3 indicates moderate severity, and the EPSS score of less than 1% suggests a low probability of exploitation at present. The flaw is not listed in CISA’s KEV catalog, implying no known mass exploitation. Attackers can exploit the flaw through a web‑based request to a protected resource without elevated privileges or local access. Despite the moderate risk rating, the potential toizing remediation.
OpenCVE Enrichment