7.6

CVE-2023-5644

Exploit

WP Mail Log < 1.1.3 – Incorrect Authorization in REST API Endpoints

WP Mail Log <= 1.1.2 - Incorrect Authorization to Authenticated (Contributor+) Data Viewing and Deletion

The WP Mail Log WordPress plugin before 1.1.3 does not correctly authorize its REST API endpoints, allowing users with the Contributor role to view and delete data that should only be accessible to Admin users.
Mögliche Gegenmaßnahme
WP Mail Log: Update to version 1.1.3, or a newer patched version
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
WpvibesWp Mail Log SwPlatformwordpress Version < 1.1.3
Weitere Schwachstelleninformationen
SystemWordPress Plugin
Produkt WP Mail Log
Version *-1.1.2
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.5% 0.387
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 7.6 2.8 4.7
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:L
134c704f-9b21-4f2e-91b3-4a467353bcc0 7.6 2.8 4.7
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:L
CWE-863 Incorrect Authorization

The product performs an authorization check when an actor attempts to access a resource or perform an action, but it does not correctly perform the check.

https://wpscan.com/vulnerability/08f1d623-0453-4103-a9aa-2d0ddb6eb69e
Third Party Advisory
Exploit
https://www.wordfence.com/threat-intel/vulnerabilities/id/bf169c9c-26f6-4af7-926e-1be34e638fd6
Third Party Advisory