Lucene search

K
cvelistWPScanCVELIST:CVE-2021-24881
HistoryJan 23, 2023 - 2:31 p.m.

CVE-2021-24881 Passster < 3.5.5.9 - Protection Bypass & Arbitrary Post Access

2023-01-2314:31:29
WPScan
www.cve.org
cve-2021-24881
passster
wordpress plugin
protection bypass
arbitrary post access
unauthenticated users

EPSS

0.002

Percentile

62.4%

The Passster WordPress plugin before 3.5.5.9 does not properly check for password, as well as that the post to be viewed is public, allowing unauthenticated users to bypass the protection offered by the plugin, and access arbitrary posts (such as private) content, by sending a specifically crafted request.

CNA Affected

[
  {
    "vendor": "Unknown",
    "product": "Passster",
    "versions": [
      {
        "status": "affected",
        "versionType": "custom",
        "version": "0",
        "lessThan": "3.5.5.9"
      }
    ],
    "defaultStatus": "unaffected",
    "collectionURL": "https://wordpress.org/plugins"
  }
]

EPSS

0.002

Percentile

62.4%

Related for CVELIST:CVE-2021-24881