CVE-2025-15489EPSS p8.1%

CVE-2025-15489CVE-2025-15489

Description

The Passster WordPress plugin before 4.2.24 does not handle input properly in an AJAX action, allowing unauthenticated users to retrieve the value of password protected content

Scoring

CVSS 5.3 ()
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
EPSS0.19% probability of exploitation · percentile 8.1% · 2026-10-05T12:00:23Z
Last modified2026-09-03
Sourced from NVD + FIRST.org EPSS. Curated for EU compliance use cases by Adam Lundqvist, Founder at SQUR.