ZeroHour

CVE-2022-2369

PoC
CVSS 3.1
4.3 medium
EPSS
<1%p52
Published
()
Modified
Description

The YaySMTP WordPress plugin before 2.2.1 does not have capability check in an AJAX action, allowing any logged in users, such as subscriber to view the Logs of the plugin

Vendors
yaycommerce
Products
yaysmtp
Ecosystems
WordPress
Weakness
CWE-862
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N

In the news

No ingested article mentions this CVE yet.