PT-2024-12287 · WordPress · Post Smtp Mailer

Erwan Lr

·

Published

2024-01-16

·

Updated

2024-01-22

·

CVE-2023-3178

CVSS v3.1

4.3

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N
Name of the Vulnerable Software and Affected Versions POST SMTP Mailer WordPress plugin versions prior to 2.5.7
Description The issue is related to improper CSRF checks in some AJAX actions. This could allow attackers to make logged-in users with the manage postman smtp capability delete arbitrary logs via a CSRF attack.
Recommendations For versions prior to 2.5.7, update to version 2.5.7 or later to resolve the issue. As a temporary workaround, consider restricting access to the AJAX actions that are vulnerable to CSRF attacks until a patch is applied.

Exploit

Fix

CSRF

Weakness Enumeration

Related Identifiers

CVE-2023-3178

Affected Products

Post Smtp Mailer