plugin

Content Protector Vulnerabilities

31 known security issues reported for the Content Protector WordPress plugin. Most recent disclosed Aug 24, 2026.

17 medium

Running Content Protector on your site? Check whether your installed version is affected.

Scan your site free

Passster – Password Protect Pages and Content < 4.3.9 - Missing Authorization

medium

The Passster – Password Protect Pages and Content plugin for WordPress is vulnerable to unauthorized access in all versions up to 4.3.9. This is due to a missing capability check on a function. This makes it possible for unauthenticated attackers to perform an unauthorized action.

CVSS:
5.3
Affected:
up to 4.3.9
Fixed in:
4.3.9
Disclosed:
Aug 24, 2026

CVE-2026-17559 on NVD →

Passster – Password Protect Pages and Content < 4.3.6 - Missing Authorization

medium

The Passster – Password Protect Pages and Content plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in versions up to 4.3.6. This makes it possible for unauthenticated attackers to perform an unauthorized action.

CVSS:
5.3
Affected:
up to 4.3.6
Fixed in:
4.3.6
Disclosed:
Aug 5, 2026

CVE-2026-16604 on NVD →

Content Protector (Passster) <= 4.3.6 - Authenticated (Contributor+) Sensitive Information Exposure

medium

The Passster – Password Protect Pages and Content plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 4.3.6. This makes it possible for authenticated attackers, with Contributor-level access and above, to extract sensitive user or configuration data.

CVSS:
4.3
Affected:
up to 4.3.6
Fixed in:
4.3.7
Disclosed:
Aug 3, 2026

CVE-2025-15674 on NVD →

Content Protector (Passster) <= 4.3.5 - Unauthenticated Category-Locked Content Disclosure

medium

The Content Protector (Passster) plugin for WordPress is vulnerable to Sensitive Information Exposure in versions up to, and including, 4.3.5. This is due to missing filtering of rendered content and excerpt fields for category-locked posts in the REST API response, allowing the core REST API to bypass the category-loc...

CVSS:
5.3
Affected:
up to 4.3.5
Fixed in:
4.3.6
Disclosed:
Jul 27, 2026

CVE-2026-16603 on NVD →

Content Protector (Passster) <= 4.3.5 - Unauthenticated Non-Public Post Content Disclosure

medium

The Content Protector (Passster) plugin for WordPress is vulnerable to Sensitive Information Exposure in versions up to, and including, 4.3.5. This is due to missing post status validation in the captcha REST endpoint, which returned post content without verifying the post was publicly published. This makes it possible...

CVSS:
5.3
Affected:
up to 4.3.5
Fixed in:
4.3.6
Disclosed:
Jul 27, 2026

CVE-2026-16602 on NVD →

Passster <= 4.2.25 - Missing Authorization

medium

The Passster – Password Protect Pages and Content plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in all versions up to, and including, 4.2.25. This makes it possible for authenticated attackers, with Contributor-level access and above, to perform an unauthorize...

CVSS:
4.3
Affected:
up to 4.2.25
Fixed in:
4.2.26
Disclosed:
Feb 12, 2026

CVE-2026-25036 on NVD →

Passster &#8211; Password Protect Pages and Content [content-protector] <= 4.2.25 (unfixed)

unknown

[en] Missing Authorization vulnerability in WP Chill Passster content-protector allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Passster: from n/a through <= 4.2.25.

Affected:
up to 4.2.25
Fix:
No patched version reported
Disclosed:
Feb 3, 2026

CVE-2026-25036 on NVD →

Passster &#8211; Password Protect Pages and Content [content-protector] < 4.2.25

unknown

[en] The Passster – Password Protect Pages and Content plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'content_protector' shortcode in all versions up to, and including, 4.2.24. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arb...

Affected:
up to 4.2.25
Fixed in:
4.2.25
Disclosed:
Jan 28, 2026

CVE-2025-14865 on NVD →

Passster – Password Protect Pages and Content <= 4.2.24 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode

medium

The Passster – Password Protect Pages and Content plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'content_protector' shortcode in all versions up to, and including, 4.2.24. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrar...

CVSS:
6.4
Affected:
up to 4.2.24
Fixed in:
4.2.25
Disclosed:
Jan 27, 2026

CVE-2025-14865 on NVD →

Passster &#8211; Password Protect Pages and Content [content-protector] <= 4.2.19 (unfixed)

unknown

[en] Insertion of Sensitive Information Into Sent Data vulnerability in WP Chill Passster content-protector allows Retrieve Embedded Sensitive Data.This issue affects Passster: from n/a through <= 4.2.19.

Affected:
up to 4.2.19
Fix:
No patched version reported
Disclosed:
Dec 18, 2025

CVE-2025-64218 on NVD →

Passster <= 4.2.19 - Unauthenticated Information Exposure

medium

The Passster – Password Protect Pages and Content plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 4.2.19. This makes it possible for unauthenticated attackers to extract sensitive user or configuration data.

CVSS:
5.3
Affected:
up to 4.2.19
Fixed in:
4.2.20
Disclosed:
Nov 12, 2025

CVE-2025-64218 on NVD →

Passster <= 4.2.18 - Authenticated (Contributor+) Stored Cross-Site Scripting

medium

The Passster plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 4.2.18 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that w...

CVSS:
6.4
Affected:
up to 4.2.18
Fixed in:
4.2.19
Disclosed:
Sep 22, 2025

CVE-2025-57926 on NVD →

Passster &#8211; Password Protect Pages and Content [content-protector] < 4.2.11

unknown

[en] The Passster – Password Protect Pages and Content plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 4.2.10 via the WordPress core search feature. This makes it possible for unauthenticated attackers to extract sensitive data from posts that have been restric...

Affected:
up to 4.2.11
Fixed in:
4.2.11
Disclosed:
Jan 7, 2025

CVE-2024-11282 on NVD →

Passster – Password Protect Pages and Content <= 4.2.10 - Unauthenticated Content Restriction Bypass to Sensitive Information Exposure

medium

The Passster – Password Protect Pages and Content plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 4.2.10 via the WordPress core search feature. This makes it possible for unauthenticated attackers to extract sensitive data from posts that have been restricted t...

CVSS:
5.3
Affected:
up to 4.2.10
Fixed in:
4.2.11
Disclosed:
Jan 6, 2025

CVE-2024-11282 on NVD →

Passster &#8211; Password Protect Pages and Content [content-protector] < 3.5.5.2

unknown

[en] The Freemius SDK, as used by hundreds of WordPress plugin and theme developers, was vulnerable to Cross-Site Request Forgery and Information disclosure due to missing capability checks and nonce protection on the _get_debug_log, _get_db_option, and the _set_db_option functions in versions up to, and including 2.4....

Affected:
up to 3.5.5.2
Fixed in:
3.5.5.2
Disclosed:
Oct 16, 2024

CVE-2022-4974 on NVD →

Passster &#8211; Password Protect Pages and Content [content-protector] < 4.2.6.5

unknown

[en] The Passster plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's content_protector shortcode in all versions up to, and including, 4.2.6.4 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with...

Affected:
up to 4.2.6.5
Fixed in:
4.2.6.5
Disclosed:
Apr 9, 2024

CVE-2024-2026 on NVD →

Passster <= 4.2.6.4 - Authenticated (Contributor+) Stored Cross-Site Scripting via content_protector Shortcode

medium

The Passster plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's content_protector shortcode in all versions up to, and including, 4.2.6.4 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contr...

CVSS:
6.4
Affected:
up to 4.2.6.4
Fixed in:
4.2.6.5
Disclosed:
Apr 4, 2024

CVE-2024-2026 on NVD →

Passster &#8211; Password Protect Pages and Content [content-protector] < 4.2.6.3

unknown

[en] The Passster – Password Protect Pages and Content plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 4.2.6.2 via API. This makes it possible for unauthenticated attackers to obtain post titles, slugs, IDs, content and other metadata including passwords of pas...

Affected:
up to 4.2.6.3
Fixed in:
4.2.6.3
Disclosed:
Feb 20, 2024

CVE-2024-0616 on NVD →

Passster – Password Protect Pages and Content <= 4.2.6.2 - Missing Authorization to Sensitive Information Exposure

medium

The Passster – Password Protect Pages and Content plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 4.2.6.2 via API. This makes it possible for unauthenticated attackers to obtain post titles, slugs, IDs, content and other metadata including passwords of password...

CVSS:
5.3
Affected:
up to 4.2.6.2
Fixed in:
4.2.6.3
Disclosed:
Feb 8, 2024

CVE-2024-0616 on NVD →

Freemius SDK <= 2.5.9 - Reflected Cross-Site Scripting via fs_request_get

medium

The Freemius SDK for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘fs_request_get’ function in versions up to, and including, 2.5.9 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute...

CVSS:
6.1
Affected:
up to 4.2.1
Fixed in:
4.2.2
Disclosed:
Jul 18, 2023

CVE-2023-33999 on NVD →

Passster &#8211; Password Protect Pages and Content [content-protector] < 3.5.5.9

unknown

[en] The Passster WordPress plugin before 3.5.5.8 does not escape the area parameter of its shortcode, which could allow users with a role as low as Contributor to perform Cross-Site Scripting attacks.

Affected:
up to 3.5.5.9
Fixed in:
3.5.5.9
Disclosed:
Jan 23, 2023

CVE-2021-24837 on NVD →

Passster &#8211; Password Protect Pages and Content [content-protector] < 3.5.5.9

unknown

[en] The Passster WordPress plugin before 3.5.5.9 does not properly check for password, as well as that the post to be viewed is public, allowing unauthenticated users to bypass the protection offered by the plugin, and access arbitrary posts (such as private) content, by sending a specifically crafted request.

Affected:
up to 3.5.5.9
Fixed in:
3.5.5.9
Disclosed:
Jan 23, 2023

CVE-2021-24881 on NVD →

Passster – Password Protection <= 3.5.5.7 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode

medium

The Passster – Password Protection plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcodes in versions up to, and including, 3.5.5.7 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers with contr...

CVSS:
6.4
Affected:
up to 3.5.5.7
Fixed in:
3.5.5.8
Disclosed:
Dec 29, 2022

CVE-2021-24837 on NVD →

Passster <= 3.5.5.8 - Missing Authentication leading to Sensitive Information Disclosure (Private Post Leakage)

medium

The Passster plugin for WordPress is vulnerable to Sensitive Information Exposure in versions up to, and including, 3.5.5.8 due to the function 'validate_input' allowing password protection bypass. This can allow unauthenticated attackers to extract basic data including private posts.

CVSS:
5.3
Affected:
up to 3.5.5.8
Fixed in:
3.5.5.9
Disclosed:
Dec 29, 2022

CVE-2021-24881 on NVD →

Passster &#8211; Password Protect Pages and Content [content-protector] < 3.5.5.5.2

unknown

[en] The Passster WordPress plugin before 3.5.5.5.2 stores the password inside a cookie named "passster" using base64 encoding method which is easy to decode. This puts the password at risk in case the cookies get leaked.

Affected:
up to 3.5.5.5.2
Fixed in:
3.5.5.5.2
Disclosed:
Oct 17, 2022

CVE-2022-3206 on NVD →

Passster <= 3.5.5.5.1 - Insecure Password Storage to Sensitive Data Exposure

medium

The Passster plugin for WordPress is vulnerable to Sensitive Data Exposure in versions up to, and including, 3.5.5.5.1 due to storing base64_encoded passwords in cookies. This could allow attackers to extract sensitive user data if those cookies get leaked. Version 3.5.5.5.1 provides a partial fix.

CVSS:
5.3
Affected:
up to 3.5.5.5.1
Fixed in:
3.5.5.5.2
Disclosed:
Sep 21, 2022

CVE-2022-3206 on NVD →

Freemius SDK <= 2.4.2 - Missing Authorization Checks

medium

The Freemius SDK, as used by hundreds of WordPress plugin and theme developers, was vulnerable to Cross-Site Request Forgery and Information disclosure due to missing capability checks and nonce protection on the _get_debug_log, _get_db_option, and the _set_db_option functions in versions up to, and including 2.4.2. An...

CVSS:
6.3
Affected:
up to 3.5.5.2
Fixed in:
3.5.5.2
Disclosed:
Mar 4, 2022

CVE-2022-4974 on NVD →

Passster &#8211; Password Protect Pages and Content [content-protector] < 3.5.5.2

unknown

The Freemius SDK, as used by hundreds of WordPress plugin and theme developers, was vulnerable to Cross-Site Request Forgery and Information disclosure due to missing capability checks and nonce protection on the _get_debug_log, _get_db_option, and the _set_db_option functions in versions up to, and including 2.4.2. An...

Affected:
up to 3.5.5.2
Fixed in:
3.5.5.2
Disclosed:
Mar 4, 2022

Passster &#8211; Password Protect Pages and Content [content-protector] < 3.5.5.2

unknown

Sensitive Information Disclosure vulnerability discovered in WordPress Passster – Password Protection plugin (versions <= 3.5.5.1).

Affected:
up to 3.5.5.2
Fixed in:
3.5.5.2
Disclosed:
Feb 28, 2022

Passster &#8211; Password Protect Pages and Content [content-protector] < 3.5.5.2

unknown

Toggle The Debug Mode via Cross-Site Request Forgery (CSRF) vulnerability discovered in WordPress Passster – Password Protection plugin (versions <= 3.5.5.1).

Affected:
up to 3.5.5.2
Fixed in:
3.5.5.2
Disclosed:
Feb 28, 2022

Passster &#8211; Password Protect Pages and Content [content-protector] < 4.2.2

unknown

** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided.

Affected:
up to 4.2.2
Fixed in:
4.2.2

CVE-2023-33999 on NVD →

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database