CVE-2026-62114: WordPress Passster plugin <= 4.3.13 - Broken Access Control vulnerability
Published Sep 11, 2026
·Updated
Unauthenticated Broken Access Control in Passster <= 4.3.13 versions.
Affected Software
1 affected component
WordPress Passster Plugin<=4.3.13
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
WordPress Passster Pluginto a version that resolves this vulnerability.Fixed in 4.3.14
Event History
Sep 11, 2026
CVE Published
via MITRE·06:12 PM
Data Sourced
via MITRE·06:12 PM
RemedyDescriptionSeverityWeakness
Frequently Asked Questions
1
Who can exploit this issue?
The vulnerability is unauthenticated, so an attacker does not need a WordPress account or other prior privileges to attempt exploitation over the network.
2
What security impact is indicated?
The supplied CVSS vector indicates low confidentiality impact and no integrity or availability impact. Exploitation is rated low complexity and does not require user interaction.