ZeroHour

CVE-2022-2352

PoC
CVSS 3.1
7.2 high
EPSS
1%p64
Published
()
Modified
Description

The Post SMTP Mailer/Email Log WordPress plugin before 2.1.7 does not have proper authorisation in some AJAX actions, which could allow high privilege users such as admin to perform blind SSRF on multisite installations for example.

Vendors
wpexperts
Products
post smtp
Ecosystems
WordPress
Weakness
CWE-918
Vector
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.