CVE-2025-15490: Unknown Passster

Medium severity, CVSS 5.3. EPSS: 0.2% chance of exploitation in the next 30 days.

The Passster WordPress plugin before 4.2.26 has a flaw in its global protection checks, allowing unauthenticated users to bypass the protection offered via crafted URLs

Affected products

  • Unknown Passster: before 4.2.26 (fixed in 4.2.26)

Published 2026-09-02. Last modified 2026-09-03.