Passster <= 3.5.5.5.1 - Insecure Password Storage to Sensitive Data Exposure

2022-09-21 00:00
Raad Haddad

Strategic Overview

Status
Patched in 3.5.5.5.2
Affected Version<= 3.5.5.5.1
CVSS5.3Medium
CVECVE-2022-3206
View all Passster – Password Protect Pages and Content vulnerabilities

Vulnerability Overview

The Passster plugin for WordPress is vulnerable to Sensitive Data Exposure in versions up to, and including, 3.5.5.5.1 due to storing base64_encoded passwords in cookies. This could allow attackers to extract sensitive user data if those cookies get leaked. Version 3.5.5.5.1 provides a partial fix.

Technical Analysis

REMEDIATION: Update to version 3.5.5.5.2, or a newer patched version --- IDENTIFIER: CWE-326 (Inadequate Encryption Strength) The product stores or transmits sensitive data using an encryption scheme that is theoretically sound, but is not strong enough for the level of protection required.

External References

Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C