CVE-2025-15489
MEDIUM5.3CVSS v3
—CVSS v2
0.19%
EPSS (exploit probability)
CWE-863CWE
Description
The Passster WordPress plugin before 4.2.24 does not handle input properly in an AJAX action, allowing unauthenticated users to retrieve the value of password protected content
CVSS v3 vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Affected routers (0)
No routers currently mapped to this CVE in our database.