PT-2022-13119 · WordPress · Customize Wordpress Emails/Alerts

Krzysztof Zając

·

Published

2022-02-28

·

Updated

2023-08-02

·

CVE-2022-0345

CVSS v3.1

4.3

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions The Customize WordPress Emails and Alerts WordPress plugin versions prior to 1.8.7
Description The issue concerns a lack of authorization and CSRF check in the bnfw search users AJAX action. This allows any authenticated users to call the action and query for user e-mail prefixes, effectively finding the first letter, then the second one, then the third one, and so on.
Recommendations For versions prior to 1.8.7, update to version 1.8.7 or later to resolve the issue. As a temporary workaround, consider restricting access to the bnfw search users AJAX action to minimize the risk of exploitation.

Exploit

Fix

Missing Authorization

CSRF

Weakness Enumeration

Related Identifiers

CVE-2022-0345

Affected Products

Customize Wordpress Emails/Alerts