Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-4w2x-h688-7527

Опубликовано: 04 сент. 2026
Источник: github
Github: Не прошло ревью
CVSS3: 5.3

Описание

The WPFunnels WordPress plugin before 3.13.0 does not perform any authorisation or nonce check in one of its opt-in submission handlers, and takes the notification recipients and subject from the request, allowing unauthenticated users to make the site send emails to arbitrary recipients with an arbitrary subject.

The WPFunnels WordPress plugin before 3.13.0 does not perform any authorisation or nonce check in one of its opt-in submission handlers, and takes the notification recipients and subject from the request, allowing unauthenticated users to make the site send emails to arbitrary recipients with an arbitrary subject.

EPSS

Процентиль: 8%
0.00182
Низкий

5.3 Medium

CVSS3

Дефекты

CWE-862

Связанные уязвимости

CVSS3: 5.3
nvd
19 дней назад

The WPFunnels WordPress plugin before 3.13.0 does not perform any authorisation or nonce check in one of its opt-in submission handlers, and takes the notification recipients and subject from the request, allowing unauthenticated users to make the site send emails to arbitrary recipients with an arbitrary subject.

EPSS

Процентиль: 8%
0.00182
Низкий

5.3 Medium

CVSS3

Дефекты

CWE-862