Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-8fp3-w5p8-ppf5

Опубликовано: 16 апр. 2024
Источник: github
Github: Не прошло ревью
CVSS3: 4.3

Описание

The Customer Reviews for WooCommerce plugin for WordPress is vulnerable to unauthorized email sending due to a missing capability check on the send_test_email() function in all versions up to, and including, 5.46.0. This makes it possible for authenticated attackers, with subscriber-level access and above, to send arbitrary test emails.

The Customer Reviews for WooCommerce plugin for WordPress is vulnerable to unauthorized email sending due to a missing capability check on the send_test_email() function in all versions up to, and including, 5.46.0. This makes it possible for authenticated attackers, with subscriber-level access and above, to send arbitrary test emails.

EPSS

Процентиль: 33%
0.00132
Низкий

4.3 Medium

CVSS3

Дефекты

CWE-862

Связанные уязвимости

CVSS3: 4.3
nvd
почти 2 года назад

The Customer Reviews for WooCommerce plugin for WordPress is vulnerable to unauthorized email sending due to a missing capability check on the send_test_email() function in all versions up to, and including, 5.46.0. This makes it possible for authenticated attackers, with subscriber-level access and above, to send arbitrary test emails.

EPSS

Процентиль: 33%
0.00132
Низкий

4.3 Medium

CVSS3

Дефекты

CWE-862