CVE-2022-3206

MEDIUM

Passster WP <3.5.5.5.2 - Info Disclosure

Title source: llm

Description

The Passster WordPress plugin before 3.5.5.5.2 stores the password inside a cookie named "passster" using base64 encoding method which is easy to decode. This puts the password at risk in case the cookies get leaked.

Scores

CVSS v3 5.9
EPSS 0.0020
EPSS Percentile 41.7%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N

Classification

CWE
CWE-319 CWE-522
Status published

Affected Products (1)

passster_project/passster < 3.5.5.5.2

Timeline

Published Oct 17, 2022
Tracked Since Feb 18, 2026