PT-2022-14001 · WordPress · Email Users

Daniel Ruf

·

Published

2022-06-13

·

Updated

2022-06-17

·

CVE-2022-1605

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N
Name of the Vulnerable Software and Affected Versions Email Users WordPress plugin versions prior to 4.8.9
Description The issue is related to the lack of a CSRF check when updating settings in the Email Users WordPress plugin. This could allow attackers to make a logged-in admin change settings via a CSRF attack, potentially altering the notification settings of arbitrary users.
Recommendations For Email Users WordPress plugin versions prior to 4.8.9, update to version 4.8.9 or later to resolve the issue.

Exploit

Fix

CSRF

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2022-1605

Affected Products

Email Users