CVE-2025-15490: Passster < 4.2.26 - Global Protection Bypass
The Passster WordPress plugin before 4.2.26 has a flaw in its global protection checks, allowing unauthenticated users to bypass the protection offered via crafted URLs
Affected Software
Event History
Frequently Asked Questions
Who can exploit this issue?
An unauthenticated remote user can exploit it; no WordPress account or user interaction is required. Exploitation involves sending crafted URLs to a site using an affected Passster version.
Which deployments are affected?
Sites using the Passster WordPress plugin before version 4.2.26 are affected when relying on its global protection functionality. The available information does not identify any additional configuration prerequisite.
What should be done if updating is not immediately possible?
The provided information does not describe a workaround. Until the plugin can be updated to version 4.2.26 or later, avoid relying on Passster global protection alone for access control.
How can I determine whether my site is exposed?
Check whether Passster is installed and whether its version is earlier than 4.2.26. Sites using the plugin's global protection feature should be treated as exposed until updated.