ZeroHour

CVE-2022-2370

PoC
CVSS 3.1
6.5 medium
EPSS
<1%p58
Published
()
Modified
Description

The YaySMTP WordPress plugin before 2.2.1 does not have capability check before displaying the Mailer Credentials in JS code for the settings, allowing any authenticated users, such as subscriber to retrieve them

Vendors
yaycommerce
Products
yaysmtp
Ecosystems
WordPress
Weakness
CWE-862
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

In the news

No ingested article mentions this CVE yet.