Description
WordPress Plugin Passster-Password Protection stores the password inside a cookie named "passster" using base64 encoding method which is easy to decode, if leaked. WordPress Plugin Passster-Password Protection version 3.5.5.5.1 is affected; prior versions may also be affected.
Remediation
Update to plugin version 3.5.5.5.2 or latest
References
https://wpscan.com/vulnerability/a8963750-62bf-403e-a906-94f371ed2a7a
https://plugins.svn.wordpress.org/content-protector/trunk/readme.txt
Related Vulnerabilities
WordPress Plugin FCChat Widget 'Upload.php' Arbitrary File Upload (2.2.13.1)
WebLogic CVE-2023-22086 Vulnerability (CVE-2023-22086)
WordPress Plugin YITH Custom Thank You Page for Woocommerce Security Bypass (1.1.6)
WordPress Plugin TableOn-WordPress Posts Table Filterable Cross-Site Scripting (1.0.0)