Home
Trends
Vulnerabilities
News
Researchers
Why dbugs?

0Xshdax

#26564of 53,634
9.7Total CVSS
Vulnerabilities · 2
Medium
2
PT-2022-16220
5.4
2022-08-08
WordPress · Yaysmtp · CVE-2022-2371
**Name of the Vulnerable Software and Affected Versions** YaySMTP WordPress plugin versions prior to 2.2.1 **Description** The issue concerns a lack of proper authorization when saving settings, allowing users with a low role, such as a subscriber, to modify them. This can be exploited to conduct a Stored Cross-Site Scripting attack due to insufficient escaping in the settings. **Recommendations** For YaySMTP WordPress plugin versions prior to 2.2.1, update to version 2.2.1 or later to resolve the issue. As a temporary workaround, consider restricting access to the settings page to prevent unauthorized changes until the update can be applied.
PT-2022-16200
4.3
2022-08-01
WordPress · Yaysmtp · CVE-2022-2369
**Name of the Vulnerable Software and Affected Versions** YaySMTP WordPress plugin versions prior to 2.2.1 **Description** The issue allows any logged-in users, such as subscribers, to view the logs of the plugin due to a lack of capability check in an AJAX action. **Recommendations** For YaySMTP WordPress plugin versions prior to 2.2.1, update to version 2.2.1 or later to resolve the issue.