CVE-2026-62114
Unauthenticated Broken Access Control in Passster <= 4.3.13 versions.
Scoring
- Severity
- MEDIUM
- CVSS base score
- 5.3
- CVSS vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
- CWE
- CWE-862
- Published
- 2026-09-11
- Last modified
- 2026-09-11
Affected products
- WP Chill Passster
Weakness type
Related vulnerabilities
- CVE-2026-81915 — In Concrete CMS below 9.5.3, Page Type update omits object-level authorization
- CVE-2026-62089 — WordPress Master Addons for Elementor plugin <= 3.2.2 - Broken Access Control vulnerability
- CVE-2026-62137 — WordPress bbPress plugin <= 2.6.14 - Sensitive Data Exposure vulnerability
- CVE-2026-62136 — WordPress Flexible Quantity – Measurement Price Calculator for WooCommerce plugin <= 2.3.21 - Broken Access Control vulnerability
- CVE-2026-62135 — WordPress Booktics plugin <= 1.0.24 - Broken Access Control vulnerability
- CVE-2026-62132 — WordPress Masteriyo - LMS plugin <= 3.4.0 - Broken Access Control vulnerability
- CVE-2026-27378 — WordPress Deposits and Partial Payments for WooCommerce plugin <= 3.1.0 - Broken Access Control vulnerability
- CVE-2026-81909 — Concrete CMS 9 through 9.5.2 is vulnerable to Missing Authorization in the orphaned-block alias route, allowing an authenticated editor to disclose and force-delete arbitrary blocks