CVE-2024-11282 is a sensitive information exposure vulnerability affecting all versions of the Passster – Password Protect Pages and Content WordPress plugin up to 4.2.10. Unauthenticated attackers can exploit this flaw through the WordPress core search feature to extract restricted content, even if it's intended for higher-level roles like administrators. With a CVSS score of 7.5 (High), this vulnerability is easily exploitable over the network with low complexity, potentially leading to significant data compromise. While there is currently no evidence of active exploitation, nor publicly available exploit code, and minimal community discussion, organizations using the affected plugin should prioritize patching.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 4.2.11CPE matchmatch criteria | cpe:2.3:a:wpchill:passster:*:*:*:*:*:wordpress:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.