PT-2024-1238 · WordPress · Post Smtp Mailer

Ulyses Saicha

·

Published

2024-01-10

·

Updated

2025-02-26

·

CVE-2023-6875

CVSS v3.1

10

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions POST SMTP Mailer – Email log, Delivery Failure Notifications and Best Mail SMTP for WordPress plugin for WordPress versions up to, and including, 2.8.7
Description The issue is related to a type juggling problem on the connect-app REST endpoint, allowing unauthenticated attackers to reset the API key and view logs, including password reset emails, which can lead to site takeover. The vulnerability is associated with weaknesses in the authorization procedure, enabling remote attackers to gain unauthorized access to protected information. With over 300,000 active installations, this vulnerability poses a significant risk.
Recommendations For versions up to, and including, 2.8.7, update to a version higher than 2.8.7 to resolve the issue. As a temporary workaround, consider restricting access to the connect-app REST endpoint until a patch is available. Additionally, restrict access to the API key used to authenticate to the mailer to minimize the risk of exploitation. Avoid using the API key in the affected endpoint until the issue is resolved.

Exploit

Fix

IDOR

Missing Authorization

Weakness Enumeration

Related Identifiers

BDU:2024-00631
CVE-2023-6875

Affected Products

Post Smtp Mailer