Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2023-5054

Опубликовано: 19 сент. 2023
Источник: nvd
CVSS3: 5.8
CVSS3: 5.3
EPSS Низкий

Описание

The Super Store Finder plugin for WordPress is vulnerable to unauthenticated arbitrary email creation and relay in versions up to, and including, 6.9.3. This is due to insufficient restrictions on the sendMail.php file that allows direct access. This makes it possible for unauthenticated attackers to send emails utilizing the vulnerable site's server, with arbitrary content. Please note that this vulnerability has already been publicly disclosed with an exploit which is why we are publishing the details without a patch available, we are attempting to initiate contact with the developer.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:superstorefinder:super_store_finder:*:*:*:*:*:wordpress:*:*
Версия до 6.9.2 (включая)

EPSS

Процентиль: 40%
0.00178
Низкий

5.8 Medium

CVSS3

5.3 Medium

CVSS3

Дефекты

Связанные уязвимости

CVSS3: 5.8
github
около 2 лет назад

The Super Store Finder plugin for WordPress is vulnerable to unauthenticated arbitrary email creation and relay in versions up to, and including, 6.9.2. This is due to insufficient restrictions on the sendMail.php file that allows direct access. This makes it possible for unauthenticated attackers to send emails utilizing the vulnerable site's server, with arbitrary content. Please note that this vulnerability has already been publicly disclosed with an exploit which is why we are publishing the details without a patch available, we are attempting to initiate contact with the developer.

EPSS

Процентиль: 40%
0.00178
Низкий

5.8 Medium

CVSS3

5.3 Medium

CVSS3

Дефекты