CVE-2025-64218: WordPress Passster plugin <= 4.2.19 - Sensitive Data Exposure vulnerability
Published Dec 18, 2025
·Updated
Insertion of Sensitive Information Into Sent Data vulnerability in WP Chill Passster content-protector allows Retrieve Embedded Sensitive Data.This issue affects Passster: from n/a through <= 4.2.19.
Affected Software
2 affected components
WP Chill Passster<=4.2.19
wordpress/passster<=4.2.19
Event History
Dec 18, 2025
CVE Published
via MITRE·07:22 AM
Data Sourced
via MITRE·07:22 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·08:16 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2025-64218?
CVE-2025-64218 has been classified as a medium severity vulnerability.
2
How do I fix CVE-2025-64218?
To fix CVE-2025-64218, you should upgrade WP Chill Passster to version 4.2.20 or later.
3
What impact does CVE-2025-64218 have on users?
CVE-2025-64218 allows attackers to retrieve embedded sensitive data, posing risks to user privacy.
4
Which versions of WP Chill Passster are affected by CVE-2025-64218?
CVE-2025-64218 affects all versions of WP Chill Passster from n/a up to and including version 4.2.19.
5
Is CVE-2025-64218 specific to any WordPress installations?
Yes, CVE-2025-64218 specifically affects WordPress installations using the WP Chill Passster plugin.