WP Vulnerability WatchVulnerability data as of September 7, 2026

Known vulnerabilities in Passster – Password Protect Pages and Content

Password Protect Pages, Posts & Content in WordPress

11Reported vulnerabilities
7.5Highest CVSS score
4.3.9Latest version
10,000+Active installs

What to do now

Update Passster – Password Protect Pages and Content to 4.3.9 or later. 11 of these have a fixed version available. Updating resolves them.

Plugin last updated: August 13, 2026 / Tested up to WordPress: 7.1 / View on wordpress.org

Reported vulnerabilities

Ordered by how urgently they need attention — whether a vulnerability is actually being exploited, and how likely exploitation is, rather than CVSS severity alone.

CVESeverityExploit probability
next 30 days
Affected versionsFixed inPublished
CVE-2024-11282 High 7.5 0.4% Before 4.2.11 4.2.11 January 7, 2025
CVE-2025-14865 Medium 6.4 0.3% 0 to 4.2.24 (inclusive) 4.2.25 January 28, 2026
CVE-2025-57926 Medium 6.4 0.2% 4.2.18 and earlier 4.2.19 September 22, 2025
CVE-2024-2026 Medium 5.4 0.5% Before 4.2.6.5 4.2.6.5 April 9, 2024
CVE-2026-17559 Medium 5.3 0.3% 4.3.3 up to (but not including) 4.3.9 4.3.9 August 21, 2026
CVE-2026-16604 Medium 5.3 0.3% Before 4.3.6 4.3.6 August 5, 2026
CVE-2026-16602 Medium 5.3 0.3% 4.3.5 and earlier 4.3.6 July 27, 2026
CVE-2026-16603 Medium 5.3 0.3% 4.3.5 and earlier 4.3.6 July 27, 2026
CVE-2025-64218 Medium 5.3 0.3% 4.2.19 and earlier 4.2.20 November 12, 2025
CVE-2026-25036 Medium 4.3 0.3% 4.2.25 and earlier 4.2.26 February 12, 2026
CVE-2025-15674 Low 2.7 0.2% 0 up to (but not including) 4.3.7 4.3.7 August 6, 2026

Sources: vulnerability records from NVD, exploitation from CISA KEV, exploit probability from EPSS. Affected versions come from CPE ranges or from the reporting CNA.