The Post SMTP Mailer/Email Log WordPress plugin before 2.1.7 does not have proper authorisation in some AJAX actions, which could allow high privilege users such as admin to perform blind SSRF on multisite installations for example.
References
Link | Resource |
---|---|
https://wpscan.com/vulnerability/dc99ac40-646a-4f8e-b2b9-dc55d6d4c55c | Exploit Patch Third Party Advisory |
Configurations
Information
Published : 2022-09-26 06:15
Updated : 2022-10-05 09:51
NVD link : CVE-2022-2352
Mitre link : CVE-2022-2352
JSON object : View
CWE
CWE-918
Server-Side Request Forgery (SSRF)
Products Affected
wpexperts
- post_smtp