PT-2022-21082 · WordPress · Passster Wordpress Plugin

Raad Haddad

·

Published

2022-10-17

·

Updated

2025-05-14

·

CVE-2022-3206

CVSS v3.1

5.9

Medium

VectorAV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Passster WordPress plugin version 3.5.5.5.2 and earlier
Description The issue arises from the storage of passwords inside a cookie named "passster" using a base64 encoding method, which is relatively easy to decode. This poses a significant risk if the cookies are leaked, as it could lead to password exposure.
Recommendations For Passster WordPress plugin versions prior to 3.5.5.5.2, update to version 3.5.5.5.2 or later to resolve the issue. As a temporary workaround, consider restricting access to the passster cookie to minimize the risk of exploitation.

Exploit

Fix

Insufficiently Protected Credentials

Cleartext Transmission of Sensitive Information

Weakness Enumeration

Related Identifiers

CVE-2022-3206

Affected Products

Passster Wordpress Plugin