PT-2024-15227 · WordPress · Fatal Error Notify

Dmitry Ignatyev

·

Published

2024-02-27

·

Updated

2025-05-01

·

CVE-2023-7202

CVSS v3.1

6.1

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:C/C:N/I:L/A:L
Name of the Vulnerable Software and Affected Versions Fatal Error Notify WordPress plugin versions prior to 1.5.3
Description The issue affects the test error AJAX action in the Fatal Error Notify WordPress plugin, which lacks authorisation and CSRF checks. This allows any authenticated users, such as subscribers, to call the action and spam the admin email address with error messages. The issue is also exploitable via CSRF.
Recommendations For versions prior to 1.5.3, update to version 1.5.3 or later to resolve the issue. As a temporary workaround, consider disabling the test error AJAX action until a patch is available. Restrict access to the admin email address to minimize the risk of spamming.

Exploit

Fix

CSRF

Weakness Enumeration

Related Identifiers

CVE-2023-7202

Affected Products

Fatal Error Notify