Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2584▼ 301 respecto a la semana anterior
Críticas / altas1355▲ 100 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 7 respecto a la semana anterior
Sin puntuar (sin CVSS)56▼ 472 respecto a la semana anterior
18 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (5.3) | 0.31% | — | PasssterAI | 11/9/2026 | 11/9/2026 | Unauthenticated Broken Access Control in Passster <= 4.3.13 versions. | |
| Aplazada | Media (5.3) | 0.21% | — | PasssterAI | 2/9/2026 | 3/9/2026 | The Passster WordPress plugin before 4.2.26 has a flaw in its global protection checks, allowing unauthenticated users to bypass the protection offered via crafted URLs | |
| Aplazada | Media (5.3) | 0.19% | — | PasssterAI | 2/9/2026 | 3/9/2026 | The Passster WordPress plugin before 4.2.24 does not handle input properly in an AJAX action, allowing unauthenticated users to retrieve the value of password protected content | |
| Aplazada | Media (5.3) | 0.35% | — | PasssterAI | 21/8/2026 | 26/8/2026 | The Passster WordPress plugin before 4.3.9 does not correctly match its own public endpoint paths when deciding which REST API requests may bypass global password protection, comparing them as an unanchored substring of the request URI rather than against the resolved route, allowing an unauthenticated attacker to… | |
| Aplazada | Baja (2.7) | 0.30% | — | PasssterAI | 6/8/2026 | 29/9/2026 | The Passster WordPress plugin before 4.3.7 does not restrict low-privilege users holding the edit_posts capability from reading globally password-protected content through the WordPress core REST API when global protection is enabled, allowing any Contributor or higher to read the content of protected pages and posts… | |
| Aplazada | Alta (7.5) | 0.43% | — | PasssterAI | 5/8/2026 | 26/8/2026 | The Passster WordPress plugin before 4.3.6 outputs password-protected block content in the public page response before verifying the password, allowing unauthenticated users to recover the protected content without knowing the password. | |
| Aplazada | Alta (7.5) | 0.43% | — | PasssterAI | 5/8/2026 | 26/8/2026 | The Passster WordPress plugin before 4.3.6 does not enforce its category-based content protection on the WordPress REST API, allowing unauthenticated users to read the full content, title, and excerpt of category-locked posts through the core REST API. | |
| Aplazada | Alta (7.5) | 0.43% | — | PasssterAI | 5/8/2026 | 26/8/2026 | The Passster WordPress plugin before 4.3.6 does not perform a post-status check before returning post content from an unauthenticated REST endpoint, allowing unauthenticated users to disclose the content of non-public (draft, private, and pending) posts on sites that have a captcha provider configured. | |
| Aplazada | Media (6.5) | 0.33% | — | Wpchill PasssterAI | 3/2/2026 | 17/6/2026 | Missing Authorization vulnerability in WP Chill Passster content-protector allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Passster: from n/a through <= 4.2.25. | |
| Aplazada | Media (6.4) | 0.28% | — | PasssterAI | 28/1/2026 | 17/6/2026 | The Passster – Password Protect Pages and Content plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'content_protector' shortcode in all versions up to, and including, 4.2.24. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject… | |
| Aplazada | Alta (7.5) | 0.35% | — | Wpchill PasssterAI | 18/12/2025 | 17/6/2026 | Insertion of Sensitive Information Into Sent Data vulnerability in WP Chill Passster content-protector allows Retrieve Embedded Sensitive Data.This issue affects Passster: from n/a through <= 4.2.19. | |
| Aplazada | Media (6.5) | 0.22% | — | Wpchill PasssterAI | 22/9/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WP Chill Passster content-protector allows Stored XSS.This issue affects Passster: from n/a through <= 4.2.18. | |
| Analizada | Alta (7.5) | 0.40% | — | Wpchill Passster | 7/1/2025 | 17/6/2026 | The Passster – Password Protect Pages and Content plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 4.2.10 via the WordPress core search feature. This makes it possible for unauthenticated attackers to extract sensitive data from posts that have been restricted… | |
| Modificada | Media (5.4) | 0.50% | — | Wpchill Passster | 9/4/2024 | 17/6/2026 | The Passster plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's content_protector shortcode in all versions up to, and including, 4.2.6.4 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with… | |
| Modificada | Media (5.3) | 0.48% | — | Wpchill Passster | 29/2/2024 | 17/6/2026 | The Passster – Password Protect Pages and Content plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 4.2.6.2 via API. This makes it possible for unauthenticated attackers to obtain post titles, slugs, IDs, content and other metadata including passwords of… | |
| Modificada | Alta (7.5) | 0.82% | — | Passster Project Passter | 23/1/2023 | 17/6/2026 | The Passster WordPress plugin before 3.5.5.9 does not properly check for password, as well as that the post to be viewed is public, allowing unauthenticated users to bypass the protection offered by the plugin, and access arbitrary posts (such as private) content, by sending a specifically crafted request. | |
| Modificada | Media (5.4) | 0.39% | — | Passster Project Passter | 23/1/2023 | 17/6/2026 | The Passster WordPress plugin before 3.5.5.8 does not escape the area parameter of its shortcode, which could allow users with a role as low as Contributor to perform Cross-Site Scripting attacks. | |
| Modificada | Media (5.9) | 0.50% | — | Passster Project Passster | 17/10/2022 | 17/6/2026 | The Passster WordPress plugin before 3.5.5.5.2 stores the password inside a cookie named "passster" using base64 encoding method which is easy to decode. This puts the password at risk in case the cookies get leaked. |