Junglewise Threat Intelligence

CVE-2025-15489: Passster password protection bypass via AJAX input validation

CVE-2025-15489 · Severity: medium · CVSS 5.3 · Published 2026-09-02

Executive brief

Passster is a WordPress plugin that protects page content behind password prompts. A flaw in its AJAX input validation allows unauthenticated users to bypass password protection and view protected content directly, exposing sensitive information without requiring the correct password.

Technical details

The plugin fails to properly validate input in an AJAX action handler (validate_input), allowing unauthenticated users to craft malicious requests that reveal password-protected content. The vulnerability is triggered by sending a POST request to wp-admin/admin-ajax.php with action=validate_input and a regex injection payload in the input parameter; the plugin then returns the protected post contents in its response. No authentication is required and the attack is network-accessible. The vulnerability was fixed in version 4.2.24.

Affected products

  • Passster Passster before 4.2.24

Timeline

  • 2026-02-17: disclosed
  • 2026-09-02: published
  • 2026-02-17: patched: Fixed in version 4.2.24

References

Related threats