Passster – Password Protect Pages and Content

Passster – Password Protect Pages and Content has 17 disclosed vulnerabilities in the WordSec catalog, reported between 2022 and 2026; all 17 are fixed as of September 2026. Their average CVSS score is 5.5, and the most serious one scores 6.4 out of 10. 2026 was the busiest year with 7 disclosures.

The most common weakness is Exposure Of Sensitive Information To An Unauthorized Actor, behind 6 of the records (35%). Other recurring categories include Cross-Site Scripting, Missing Authorization.

Every one of the 17 issues recorded for Passster – Password Protect Pages and Content has a vendor fix available, so running the current release closes all known holes.

12 independent researchers contributed these findings, most of them (3) reported by Revanth Hari Narayana Matte. Passster – Password Protect Pages and Content is installed on roughly 10,000 WordPress sites, so each unpatched flaw has a wide blast radius. The current release is tested up to WordPress 7.1.

01234567891008.12.2013Today04.03.20226.3Freemius SDK <= 2.4.2 - Missing Authorization Checks CVSS 6.3 · 04.03.202221.09.20225.3Passster <= 3.5.5.5.1 - Insecure Password Storage to Sensitive Data Exposure CVSS 5.3 · 21.09.202229.12.20225.3Passster <= 3.5.5.8 - Missing Authentication leading to Sensitive Information Disclosure (Private Post Leakage) CVSS 5.3 · 29.12.20226.4Passster – Password Protection <= 3.5.5.7 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode CVSS 6.4 · 29.12.202218.07.20236.1Freemius SDK <= 2.5.9 - Reflected Cross-Site Scripting via fs_request_get CVSS 6.1 · 18.07.202308.02.20245.3Passster – Password Protect Pages and Content <= 4.2.6.2 - Missing Authorization to Sensitive Information Exposure CVSS 5.3 · 08.02.202404.04.20246.4Passster <= 4.2.6.4 - Authenticated (Contributor+) Stored Cross-Site Scripting via content_protector Shortcode CVSS 6.4 · 04.04.202406.01.20255.3Passster – Password Protect Pages and Content <= 4.2.10 - Unauthenticated Content Restriction Bypass to Sensitive Information Exposure CVSS 5.3 · 06.01.202522.09.20256.4Passster <= 4.2.18 - Authenticated (Contributor+) Stored Cross-Site Scripting CVSS 6.4 · 22.09.202512.11.20255.3Passster <= 4.2.19 - Unauthenticated Information Exposure CVSS 5.3 · 12.11.202527.01.20266.4Passster – Password Protect Pages and Content <= 4.2.24 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode CVSS 6.4 · 27.01.202612.02.20264.3Passster <= 4.2.25 - Missing Authorization CVSS 4.3 · 12.02.202627.07.20265.3Content Protector (Passster) <= 4.3.5 - Unauthenticated Category-Locked Content Disclosure CVSS 5.3 · 27.07.20265.3Content Protector (Passster) <= 4.3.5 - Unauthenticated Non-Public Post Content Disclosure CVSS 5.3 · 27.07.202603.08.20264.3Content Protector (Passster) <= 4.3.6 - Authenticated (Contributor+) Sensitive Information Exposure CVSS 4.3 · 03.08.202605.08.20265.3Passster – Password Protect Pages and Content < 4.3.6 - Missing Authorization CVSS 5.3 · 05.08.202624.08.20265.3Passster – Password Protect Pages and Content < 4.3.9 - Missing Authorization CVSS 5.3 · 24.08.2026

Strategic Overview

Avg CVSSMedium
5.5/ 10
Patch Coverage100%
Open

0

Fixed

17

Get automatic notifications for all Passster – Password Protect Pages and Content vulnerabilities before they are exploited.

Highest severity on recordCVSS 6.4CVE-2025-14865

Passster – Password Protect Pages and Content <= 4.2.24 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode

Read the full analysis

Vulnerability Records

17 records
2026-08-24 00:00CVE-2026-17559
5.3
Medium
Erwan LRYes
2026-08-05 00:00CVE-2026-16604
5.3
Medium
Revanth Hari Narayana MatteYes
2026-08-03 00:00CVE-2025-15674
4.3
Medium
Pierre RudloffYes
2026-07-27 00:00CVE-2026-16603
5.3
Medium
Revanth Hari Narayana MatteYes
2026-07-27 00:00CVE-2026-16602
5.3
Medium
Revanth Hari Narayana MatteYes
2026-02-12 00:00CVE-2026-25036
4.3
Medium
johskaYes
2026-01-27 00:00CVE-2025-14865
6.4
Medium
Muhammad Yudha - DJYes
2025-11-12 00:00CVE-2025-64218
5.3
Medium
Que Thanh Tuan - Blue RockYes
2025-09-22 00:00CVE-2025-57926
6.4
Medium
Que Thanh Tuan - Blue RockYes
2025-01-06 00:00CVE-2024-11282
5.3
Medium
Francesco CarlucciYes
Showing 1–10 of 17 reports
Passster – Password Protect Pages and Content banner
Latestv4.3.15

Passster – Password Protect Pages and Content

WP Chill

Author

WP Chill

4.2(60)
84/100
Last Updated
2026-09-10 (2d ago)
Active Installs
10,000+
Downloads
662,309
Requires WP
6.5+
Requires PHP
7.2+
Tested up to
WP 7.1
Created
2013-12-08 (13y ago)

Password Protect Pages, Posts & Content in WordPress Passster is an all-in-one plugin to password protect pages, content, or your entire site in seconds—quick, secure, and easy to use. Passster offers three protection modes to cover every use case you may think of when it comes to password protecting your WordPress website. Passster Pro – Even more protection features when making a purchase Multiple Passwords & Password Lists – Assign multiple passwords for different users. – Create and manage large password lists for easy control. Quick & Bulk Edit for Password Protection – Use WordPress Quick Edit and Bulk Edit to protect multiple pages instantly. Unlock Content by User Role or Email – Automatically grant access to specific users or email addresses. Password Expiration & Usage Limits – Set passwords to expire after a number of uses, first use, or by a time limit (hours, days, weeks). – Track which passwords were used and when they will expire. Generate Unlock Links – Create encrypted unlock links so users can access content without entering a password. – Automatically shorten links with Bit.ly for easy sharing. WooCommerce Protection & Sales – Protect WooCommerce pages, products, and checkout with a password. – Sell access to protected content—generate and email passwords automatically after purchase. Detailed Password Usage Statistics – Track when and how often passwords are used. – View first usage date, IP (optional), and browser details. Quick Comparison (Free vs. Pro) Free Version: ✔ Protect sections of pages using shortcodes or blocks. ✔ Secure entire pages and posts. ✔ Automatically protect child pages with a single click. ✔ Lock down your entire site with a password. ✔ Unlock protected content without refreshing the page. ✔ Customize the design, labels, and descriptions of the password form. ✔ Use cookies to grant access across multiple protected areas. Pro Version: ✔ Everything in the free version, plus: ✔ Protect content with multiple passwords or password lists. ✔ Quickly set up password protection via Quick Edit or Bulk Edit. ✔ Protect content using Google reCAPTCHA or hCAPTCHA. ✔ Unlock protected content by user role or email. ✔ Set passwords to expire based on usage limits or time intervals. ✔ Generate encrypted unlock links for seamless access. ✔ Track and prevent concurrent password sharing. ✔ Secure WooCommerce products and store pages. ✔ Sell access to protected content via WooCommerce integration. ✔ Detailed statistics on password usage and lists. Get it now on passster.com/ Documentation Learn more about this plugin in our official documentation Support Free users: Ask in our forum Pro users: Get priority help

Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C