Plugin Vulnerability Hub
Plugin 10 known issues Latest disclosed Feb 12, 2026

Passster – Password Protect Pages and Content Vulnerabilities

Review known vulnerability records for the WordPress plugin Passster – Password Protect Pages and Content (`content-protector`), including severity, CVE references, affected versions, and patch status.

Recent tracked CVEs on this page include CVE-2026-25036, CVE-2025-14865 and CVE-2025-64218, so operators can jump from disclosure to patch validation without scanning the full feed first.

Known Records
10
High or Critical
0
Patch Coverage
100%
Last Updated
Feb 16, 2026
Priority CVE Quick Links

Fast paths into Passster – Password Protect Pages and Content CVE reports

Start with the highest-signal CVE records for this WordPress plugin before scanning the full vulnerability feed.

Indexed CVEs
10
CVE-2025-14865 Medium 4.2.25
CVE-2025-14865 Passster – Password Protect Pages and Content Stored Cross-Site Scripting

Passster – Password Protect Pages and Content <= 4.2.24 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode

CVE-2025-57926 Medium 4.2.19
CVE-2025-57926 Passster – Password Protect Pages and Content Stored Cross-Site Scripting

Passster <= 4.2.18 - Authenticated (Contributor+) Stored Cross-Site Scripting

CVE-2024-2026 Medium 4.2.6.5
CVE-2024-2026 Passster – Password Protect Pages and Content Stored Cross-Site Scripting

Passster <= 4.2.6.4 - Authenticated (Contributor+) Stored Cross-Site Scripting via content_protector Shortcode

CVE-2021-24837 Medium 3.5.5.8
CVE-2021-24837 Passster – Password Protect Pages and Content Stored Cross-Site Scripting

Passster – Password Protection <= 3.5.5.7 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode

CVE-2025-64218 Medium 4.2.20
CVE-2025-64218 Passster – Password Protect Pages and Content Sensitive Information Exposure

Passster <= 4.2.19 - Unauthenticated Information Exposure

CVE-2024-11282 Medium 4.2.11
CVE-2024-11282 Passster – Password Protect Pages and Content Sensitive Information Exposure

Passster – Password Protect Pages and Content <= 4.2.10 - Unauthenticated Content Restriction Bypass to Sensitive Information Exposure

CVE-2024-0616 Medium 4.2.6.3
CVE-2024-0616 Passster – Password Protect Pages and Content Sensitive Information Exposure

Passster – Password Protect Pages and Content <= 4.2.6.2 - Missing Authorization to Sensitive Information Exposure

CVE-2021-24881 Medium 3.5.5.9
CVE-2021-24881 Passster – Password Protect Pages and Content Sensitive Information Exposure

Passster <= 3.5.5.8 - Missing Authentication leading to Sensitive Information Disclosure (Private Post Leakage)

Coverage Snapshot

What this page helps you verify fast

This hub clusters every indexed record for Passster – Password Protect Pages and Content so operators can confirm whether a disclosed issue maps to the installed slug, version range, and patch path.

Patch Visibility
10 records include a published patch path, leaving 0 with no listed safe release yet.
Severity Mix
0 critical and 0 high severity findings.
Recent CVEs
CVE-2026-25036, CVE-2025-14865 and CVE-2025-64218
Reference Workflow
Jump from the hub into the full report when you need remediation notes, exploit context, CVSS vectors, or source references.
Triage First

Open the records most likely to drive action

These recent records surface the CVE strings, patch cues, and direct report links most operators need first.

Known Vulnerabilities

Reports for Passster – Password Protect Pages and Content

Sorted by latest disclosure date so newly published issues surface first.

Plugin Medium Patched: Yes CVE-2026-25036
CVE-2026-25036: Passster <= 4.2.25 - Missing Authorization

The Passster – Password Protect Pages and Content plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in all versions up to, and including, 4.2.25. This makes it possible for authenticated attackers, with Contributor-level acc...

Published
Feb 12, 2026
Patched Release
4.2.26
Affected Versions
Versions up to 4.2.25
Next Step
Update to 4.2.26 or newer if supported.
Plugin Medium Patched: Yes CVE-2025-14865
CVE-2025-14865: Passster – Password Protect Pages and Content <= 4.2.24 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode

The Passster – Password Protect Pages and Content plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'content_protector' shortcode in all versions up to, and including, 4.2.24. This makes it possible for authenticated attackers, with Contributor-le...

Published
Jan 27, 2026
Patched Release
4.2.25
Affected Versions
Versions up to 4.2.24
Next Step
Update to 4.2.25 or newer if supported.
Plugin Medium Patched: Yes CVE-2025-64218
CVE-2025-64218: Passster <= 4.2.19 - Unauthenticated Information Exposure

The Passster – Password Protect Pages and Content plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 4.2.19. This makes it possible for unauthenticated attackers to extract sensitive user or configuration data.

Published
Nov 12, 2025
Patched Release
4.2.20
Affected Versions
Versions up to 4.2.19
Next Step
Update to 4.2.20 or newer if supported.
Plugin Medium Patched: Yes CVE-2025-57926
CVE-2025-57926: Passster <= 4.2.18 - Authenticated (Contributor+) Stored Cross-Site Scripting

The Passster plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 4.2.18 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inje...

Published
Sep 22, 2025
Patched Release
4.2.19
Affected Versions
Versions up to 4.2.18
Next Step
Update to 4.2.19 or newer if supported.
Plugin Medium Patched: Yes CVE-2024-11282
CVE-2024-11282: Passster – Password Protect Pages and Content <= 4.2.10 - Unauthenticated Content Restriction Bypass to Sensitive Information Exposure

The Passster – Password Protect Pages and Content plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 4.2.10 via the WordPress core search feature. This makes it possible for unauthenticated attackers to extract sensitive dat...

Published
Jan 06, 2025
Patched Release
4.2.11
Affected Versions
Versions up to 4.2.10
Next Step
Update to 4.2.11 or newer if supported.
Plugin Medium Patched: Yes CVE-2024-2026
CVE-2024-2026: Passster <= 4.2.6.4 - Authenticated (Contributor+) Stored Cross-Site Scripting via content_protector Shortcode

The Passster plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's content_protector shortcode in all versions up to, and including, 4.2.6.4 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible...

Published
Apr 04, 2024
Patched Release
4.2.6.5
Affected Versions
Versions up to 4.2.6.4
Next Step
Update to 4.2.6.5 or newer if supported.
Plugin Medium Patched: Yes CVE-2024-0616
CVE-2024-0616: Passster – Password Protect Pages and Content <= 4.2.6.2 - Missing Authorization to Sensitive Information Exposure

The Passster – Password Protect Pages and Content plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 4.2.6.2 via API. This makes it possible for unauthenticated attackers to obtain post titles, slugs, IDs, content and other...

Published
Feb 08, 2024
Patched Release
4.2.6.3
Affected Versions
Versions up to 4.2.6.2
Next Step
Update to 4.2.6.3 or newer if supported.
Plugin Medium Patched: Yes CVE-2021-24881
CVE-2021-24881: Passster <= 3.5.5.8 - Missing Authentication leading to Sensitive Information Disclosure (Private Post Leakage)

The Passster plugin for WordPress is vulnerable to Sensitive Information Exposure in versions up to, and including, 3.5.5.8 due to the function 'validate_input' allowing password protection bypass. This can allow unauthenticated attackers to extract basic data including private p...

Published
Dec 29, 2022
Patched Release
3.5.5.9
Affected Versions
Versions up to 3.5.5.8
Next Step
Update to 3.5.5.9 or newer if supported.
Plugin Medium Patched: Yes CVE-2021-24837
CVE-2021-24837: Passster – Password Protection <= 3.5.5.7 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode

The Passster – Password Protection plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcodes in versions up to, and including, 3.5.5.7 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possibl...

Published
Dec 29, 2022
Patched Release
3.5.5.8
Affected Versions
Versions up to 3.5.5.7
Next Step
Update to 3.5.5.8 or newer if supported.
Plugin Medium Patched: Yes CVE-2022-3206
CVE-2022-3206: Passster <= 3.5.5.5.1 - Insecure Password Storage to Sensitive Data Exposure

The Passster plugin for WordPress is vulnerable to Sensitive Data Exposure in versions up to, and including, 3.5.5.5.1 due to storing base64_encoded passwords in cookies. This could allow attackers to extract sensitive user data if those cookies get leaked. Version 3.5.5.5.1 prov...

Published
Sep 21, 2022
Patched Release
3.5.5.5.2
Affected Versions
Versions up to 3.5.5.5.1
Next Step
Update to 3.5.5.5.2 or newer if supported.