CVE-2026-25036: WordPress Passster plugin <= 4.2.25 - Broken Access Control vulnerability
Published Feb 3, 2026
·Updated
Missing Authorization vulnerability in WP Chill Passster content-protector allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Passster: from n/a through <= 4.2.25.
Affected Software
2 affected components
WP Chill Passster<=4.2.25
wordpress/passster<=4.2.25
Event History
Feb 3, 2026
CVE Published
via MITRE·02:08 PM
Data Sourced
via MITRE·02:08 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·03:16 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2026-25036?
CVE-2026-25036 is classified as a Broken Access Control vulnerability with a high potential for exploitation.
2
How do I fix CVE-2026-25036?
To mitigate CVE-2026-25036, users should upgrade the WP Chill Passster plugin to version 4.2.26 or later.
3
What versions of Passster are affected by CVE-2026-25036?
CVE-2026-25036 affects WP Chill Passster plugin versions up to and including 4.2.25.
4
What impact does CVE-2026-25036 have on WordPress sites?
Exploitation of CVE-2026-25036 allows unauthorized access to restricted content, compromising site security.
5
Is user authentication a problem with CVE-2026-25036?
Yes, CVE-2026-25036 indicates a missing authorization check in the Passster plugin, leading to issues with user authentication.