Passster <= 3.5.5.8 - Missing Authentication leading to Sensitive Information Disclosure (Private Post Leakage)

2022-12-29 00:00
dc11

Strategic Overview

Status
Patched in 3.5.5.9
Affected Version<= 3.5.5.8
CVSS5.3Medium
CVECVE-2021-24881
View all Passster – Password Protect Pages and Content vulnerabilities

Vulnerability Overview

The Passster plugin for WordPress is vulnerable to Sensitive Information Exposure in versions up to, and including, 3.5.5.8 due to the function 'validate_input' allowing password protection bypass. This can allow unauthenticated attackers to extract basic data including private posts.

Technical Analysis

REMEDIATION: Update to version 3.5.5.9, or a newer patched version --- IDENTIFIER: CWE-862 (Missing Authorization) The product does not perform an authorization check when an actor attempts to access a resource or perform an action.

External References

Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C