Lucene search

K
cvelistPatchstackCVELIST:CVE-2022-42699
HistoryDec 06, 2022 - 10:00 p.m.

CVE-2022-42699 WordPress Easy WP SMTP Plugin <= 1.5.1 is vulnerable to Remote Code Execution (RCE)

2022-12-0622:00:55
CWE-94
Patchstack
www.cve.org
2
cve-2022-42699
easy wp smtp
rce
vulnerability
wordpress

CVSS3

9.1

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

HIGH

User Interaction

NONE

Scope

CHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H

AI Score

9.8

Confidence

High

EPSS

0.003

Percentile

66.2%

Auth. Remote Code Execution vulnerability inย Easy WP SMTP plugin <= 1.5.1 onย WordPress.

CNA Affected

[
  {
    "collectionURL": "https://wordpress.org/plugins",
    "defaultStatus": "unaffected",
    "product": "Easy WP SMTP",
    "vendor": "WPecommerce, Alexanderfoxc",
    "versions": [
      {
        "changes": [
          {
            "at": "1.5.2",
            "status": "unaffected"
          }
        ],
        "lessThanOrEqual": "1.5.1",
        "status": "affected",
        "version": "n/a",
        "versionType": "custom"
      }
    ]
  }
]

CVSS3

9.1

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

HIGH

User Interaction

NONE

Scope

CHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H

AI Score

9.8

Confidence

High

EPSS

0.003

Percentile

66.2%

Related for CVELIST:CVE-2022-42699