Описание
The YaySMTP WordPress plugin before 2.2.1 does not have capability check before displaying the Mailer Credentials in JS code for the settings, allowing any authenticated users, such as subscriber to retrieve them
Ссылки
- ExploitThird Party Advisory
- ExploitThird Party Advisory
Уязвимые конфигурации
Конфигурация 1Версия до 2.2.1 (исключая)
cpe:2.3:a:yaycommerce:yaysmtp:*:*:*:*:*:wordpress:*:*
EPSS
Процентиль: 67%
0.00541
Низкий
6.5 Medium
CVSS3
Дефекты
CWE-862
Связанные уязвимости
CVSS3: 6.5
github
больше 3 лет назад
The YaySMTP WordPress plugin before 2.2.1 does not have capability check before displaying the Mailer Credentials in JS code for the settings, allowing any authenticated users, such as subscriber to retrieve them
EPSS
Процентиль: 67%
0.00541
Низкий
6.5 Medium
CVSS3
Дефекты
CWE-862