Executive brief
Passster is a WordPress plugin that protects sensitive content on websites. The plugin has a flaw in its global protection checks that allows unauthenticated users to bypass content protection by appending specific query parameters to URLs, potentially exposing protected pages and posts to unauthorized access.
Technical details
The vulnerability is an authentication bypass in Passster's global protection mechanism. The plugin fails to properly validate protection rules when specific query parameters (elementor-preview=1 or lc_action_launch_editing=1) are appended to URLs, allowing unauthenticated users to view protected content. The flaw affects versions before 4.2.26 and is fixed in version 4.2.26. Attack vectors include crafted URLs with the bypass parameters, requiring no authentication or user interaction beyond accessing the modified URL.
Affected products
- Passster Passster before 4.2.26
Timeline
- 2026-02-17: advisory: Vulnerability publicly disclosed
- 2026-02-17: patched: Fixed in version 4.2.26