CVE-2024-0616

MEDIUM

Passster WordPress <4.2.6.2 - Info Disclosure

Title source: llm
STIX 2.1

Description

The Passster – Password Protect Pages and Content plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 4.2.6.2 via API. This makes it possible for unauthenticated attackers to obtain post titles, slugs, IDs, content and other metadata including passwords of password-protected posts and pages.

Scores

CVSS v3 5.3
EPSS 0.0049
EPSS Percentile 38.1%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-200
Status published
Products (2)
wpchill/passster < 4.2.6.3
wpchill/Passster – Password Protect Pages and Content < 4.2.6.2
Published Feb 29, 2024
Tracked Since Feb 18, 2026