CVE-2021-24881: Passster < 3.5.5.9 - Protection Bypass & Arbitrary Post Access
The Passster WordPress plugin before 3.5.5.9 does not properly check for password, as well as that the post to be viewed is public, allowing unauthenticated users to bypass the protection offered by the plugin, and access arbitrary posts (such as private) content, by sending a specifically crafted request.
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID for this Passster WordPress plugin vulnerability?
The vulnerability ID for this Passster WordPress plugin vulnerability is CVE-2021-24881.
What is the severity of CVE-2021-24881?
The severity of CVE-2021-24881 is high, with a severity value of 7.5.
What does the Passster WordPress plugin vulnerability CVE-2021-24881 allow?
The Passster WordPress plugin vulnerability CVE-2021-24881 allows unauthenticated users to bypass the plugin's protection and access arbitrary posts, including private content.
How can the Passster WordPress plugin vulnerability CVE-2021-24881 be exploited?
The Passster WordPress plugin vulnerability CVE-2021-24881 can be exploited by sending a specifically crafted request.
What is the affected version of the Passster WordPress plugin for CVE-2021-24881?
The affected version of the Passster WordPress plugin for CVE-2021-24881 is version 3.5.5.9.