Extension WordPress
Vulnérabilités Passster – Password Protect Pages and Content
Cette page rassemble les failles publiées pour Passster – Password Protect Pages and Content, leurs plages de versions affectées et les correctifs signalés dans la base locale.
Historique de sécurité
CVE et vulnérabilités de Passster – Password Protect Pages and Content
12 fiches
Passster <= 4.2.25 – Missing Authorization
The Passster – Password Protect Pages and Content plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in all versions up to, and including, 4.2.25. This makes it possible for…
*-4.2.25
4.2.26
12/02/2026
Passster – Password Protect Pages and Content <= 4.2.24 – Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode
The Passster – Password Protect Pages and Content plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'content_protector' shortcode in all versions up to, and including, 4.2.24. This makes it possible for authenticated attackers, with…
*-4.2.24
4.2.25
27/01/2026
Passster <= 4.2.19 – Unauthenticated Information Exposure
The Passster – Password Protect Pages and Content plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 4.2.19. This makes it possible for unauthenticated attackers to extract sensitive user or configuration…
*-4.2.19
4.2.20
12/11/2025
Passster <= 4.2.18 – Authenticated (Contributor+) Stored Cross-Site Scripting
The Passster plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 4.2.18 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above,…
*-4.2.18
4.2.19
22/09/2025
Passster – Password Protect Pages and Content <= 4.2.10 – Unauthenticated Content Restriction Bypass to Sensitive Information Exposure
The Passster – Password Protect Pages and Content plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 4.2.10 via the WordPress core search feature. This makes it possible for unauthenticated attackers…
*-4.2.10
4.2.11
06/01/2025
Passster <= 4.2.6.4 – Authenticated (Contributor+) Stored Cross-Site Scripting via content_protector Shortcode
The Passster plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's content_protector shortcode in all versions up to, and including, 4.2.6.4 due to insufficient input sanitization and output escaping on user supplied attributes. This makes…
*-4.2.6.4
4.2.6.5
04/04/2024
Passster – Password Protect Pages and Content <= 4.2.6.2 – Missing Authorization to Sensitive Information Exposure
The Passster – Password Protect Pages and Content plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 4.2.6.2 via API. This makes it possible for unauthenticated attackers to obtain post titles,…
*-4.2.6.2
4.2.6.3
08/02/2024
Freemius SDK <= 2.5.9 – Reflected Cross-Site Scripting via fs_request_get
The Freemius SDK for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘fs_request_get’ function in versions up to, and including, 2.5.9 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to…
*-4.2.1
4.2.2
18/07/2023
Passster <= 3.5.5.8 – Missing Authentication leading to Sensitive Information Disclosure (Private Post Leakage)
The Passster plugin for WordPress is vulnerable to Sensitive Information Exposure in versions up to, and including, 3.5.5.8 due to the function 'validate_input' allowing password protection bypass. This can allow unauthenticated attackers to extract basic data including private…
*-3.5.5.8
3.5.5.9
29/12/2022
Passster – Password Protection <= 3.5.5.7 – Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode
The Passster – Password Protection plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcodes in versions up to, and including, 3.5.5.7 due to insufficient input sanitization and output escaping on user supplied attributes. This…
*-3.5.5.7
3.5.5.8
29/12/2022
Passster <= 3.5.5.5.1 – Insecure Password Storage to Sensitive Data Exposure
The Passster plugin for WordPress is vulnerable to Sensitive Data Exposure in versions up to, and including, 3.5.5.5.1 due to storing base64_encoded passwords in cookies. This could allow attackers to extract sensitive user data if those cookies get…
*-3.5.5.5.1
3.5.5.5.2
21/09/2022
Freemius SDK <= 2.4.2 – Missing Authorization Checks
The Freemius SDK, as used by hundreds of WordPress plugin and theme developers, was vulnerable to Cross-Site Request Forgery and Information disclosure due to missing capability checks and nonce protection on the _get_debug_log, _get_db_option, and the _set_db_option functions…
[*, 3.5.5.2)
3.5.5.2
04/03/2022
Extensions également surveillés
WP Commander
Rechercher dans toute la base WordPress
Utilisez la recherche globale pour retrouver une extension, un thème, une CVE ou un identifiant de vulnérabilité.