Passster <= 3.5.5.5.1 - Insecure Password Storage to Sensitive Data Exposure
2022-09-21 00:00
Raad HaddadStrategic Overview
StatusPatched in 3.5.5.5.2
Affected PluginPassster – Password Protect Pages and Content
Affected Version
<= 3.5.5.5.1CVSS5.3Medium
CVE
CVE-2022-3206Vulnerability Overview
The Passster plugin for WordPress is vulnerable to Sensitive Data Exposure in versions up to, and including, 3.5.5.5.1 due to storing base64_encoded passwords in cookies. This could allow attackers to extract sensitive user data if those cookies get leaked. Version 3.5.5.5.1 provides a partial fix.
Technical Analysis
REMEDIATION: Update to version 3.5.5.5.2, or a newer patched version --- IDENTIFIER: CWE-326 (Inadequate Encryption Strength) The product stores or transmits sensitive data using an encryption scheme that is theoretically sound, but is not strong enough for the level of protection required.
External References
Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C