Lucene search

K
cvelistWPScanCVELIST:CVE-2022-2369
HistoryAug 01, 2022 - 12:52 p.m.

CVE-2022-2369 YaySMTP < 2.2.1 - Subscriber+ Logs Disclosure

2022-08-0112:52:42
CWE-862
WPScan
www.cve.org
8
yaysmtp
plugin
logs disclosure
wordpress

AI Score

4.9

Confidence

High

EPSS

0.001

Percentile

24.8%

The YaySMTP WordPress plugin before 2.2.1 does not have capability check in an AJAX action, allowing any logged in users, such as subscriber to view the Logs of the plugin

CNA Affected

[
  {
    "product": "YaySMTP – Simple WP SMTP Mail",
    "vendor": "Unknown",
    "versions": [
      {
        "lessThan": "2.2.1",
        "status": "affected",
        "version": "2.2.1",
        "versionType": "custom"
      }
    ]
  }
]

AI Score

4.9

Confidence

High

EPSS

0.001

Percentile

24.8%

Related for CVELIST:CVE-2022-2369