SEPTEMBER 17, 2026
Live Feed
Back to database
Case File

CVE-2025-15489

MEDIUM · CVSS 5.3 EPSS 0.19%

Source: NVD + CISA KEV + EPSS · Published 2026-09-02 · Last synced 2026-09-17

CyberRota Analysis

AI-Generated

The Passster WordPress plugin versions prior to 4.2.24 are vulnerable due to improper input handling in an AJAX action, which allows unauthenticated users to access password-protected content. This could lead to unauthorized exposure of sensitive information. WordPress site administrators using this plugin should prioritize updating to the latest version to mitigate potential risks.

CVE
CVE-2025-15489
Severity
MEDIUM
CVSS
5.3
EPSS
0.19%
WordPress

Original NVD Description

The Passster WordPress plugin before 4.2.24 does not handle input properly in an AJAX action, allowing unauthenticated users to retrieve the value of password protected content