Junglewise Threat Intelligence

CVE-2026-62114: Passster broken access control vulnerability

CVE-2026-62114 · Severity: medium · CVSS 5.3 · Published 2026-09-11

Vendors: WP Chill.

Executive brief

Passster is a WordPress plugin for protecting page content with passwords. Versions up to 4.3.13 contain a flaw that allows unauthenticated attackers to bypass access controls and view pages or data they should not be able to access. This could expose sensitive information that website owners intended to restrict to specific users.

Technical details

The vulnerability is a broken access control flaw in Passster versions up to 4.3.13, classified as OWASP A1. An unauthenticated attacker can bypass the plugin's password protection mechanism to access protected pages and perform unauthorized actions. No authentication or user interaction is required to exploit this vulnerability. An attacker could view restricted content and bypass intended access restrictions. The issue was patched in version 4.3.14.

Affected products

  • WP Chill Passster <= 4.3.13

Timeline

  • 2026-08-30: disclosed: Vulnerability reported to Patchstack
  • 2026-09-11: advisory: Published by Patchstack
  • 2026: patched: Fix available in version 4.3.14

References