Passster Project develops a password-management plugin with a narrow product scope, where disclosed vulnerabilities center on credential handling and data transmission, including cleartext transmission of sensitive information and insufficiently protected credentials. Current severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Passster Project over time
Signals from CVEs in this vendor scope (3 CVEs).
3 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2021-24881HIGH The Passster WordPress plugin before 3.5.5.9 does not properly check for password, as well as that the post to be viewed is public, allowing unauthenticated users to bypass the pro | Jan 23, 2023 | 7.5 | 24 | NO | NO |
CVE-2022-3206MEDIUM The Passster WordPress plugin before 3.5.5.5.2 stores the password inside a cookie named "passster" using base64 encoding method which is easy to decode. This puts the password at | Oct 17, 2022 | 5.9 | 21 | NO | NO |
CVE-2021-24837MEDIUM The Passster WordPress plugin before 3.5.5.8 does not escape the area parameter of its shortcode, which could allow users with a role as low as Contributor to perform Cross-Site Sc | Jan 23, 2023 | 5.4 | 20 | NO | NO |
Signals from CVEs in this vendor scope (3 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Passster Project.
Media articles that mention a CVE ID that affects a product developed by Passster Project — matched by CVE ID, not by vendor name.