PT-2022-23317 · WordPress · Mailoptin

Muhammad Daffa

·

Published

2022-09-23

·

Updated

2022-09-26

·

CVE-2022-36340

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L
Name of the Vulnerable Software and Affected Versions MailOptin plugin versions 1.2.49.0 and earlier
Description The issue concerns an Unauthenticated Optin Campaign Cache Deletion vulnerability. This vulnerability affects the MailOptin plugin at WordPress, allowing for unauthenticated cache deletion of opt-in campaigns.
Recommendations For MailOptin plugin versions 1.2.49.0 and earlier, update to a version later than 1.2.49.0 to resolve the issue.

Fix

Missing Authorization

Weakness Enumeration

Related Identifiers

CVE-2022-36340

Affected Products

Mailoptin