Unauthorized Access Vulnerability in Passster Plugin for WordPress
CVE-2025-15674
Key Information:
Badges
What is CVE-2025-15674?
The Passster WordPress plugin prior to version 4.3.7 contains a vulnerability that allows users with low privileges, specifically those holding the edit_posts capability, to bypass password protection on globally protected content. When global protection is enabled, this flaw allows contributors and higher roles to access the content of secured pages and posts through the WordPress core REST API without requiring the associated password, leading to potential exposure of sensitive information.
Affected Version(s)
Passster 0 < 4.3.7
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V3.1
Timeline
- ๐ก
Public PoC available
- ๐พ
Exploit known to exist
Vulnerability published
Vulnerability Reserved