PT-2024-39400 · WordPress · Wp Helper Premium

Francesco Carlucci

·

Published

2024-10-09

·

Updated

2024-12-20

·

CVE-2024-9065

CVSS v3.1

5.3

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
Name of the Vulnerable Software and Affected Versions WP Helper Premium plugin for WordPress versions up to, and including, 4.6.1
Description The issue is related to a missing capability check on the whp smtp send mail test function, allowing unauthenticated attackers to send emails with any content from the vulnerable WordPress instance to any recipient.
Recommendations For versions up to, and including, 4.6.1, consider disabling the whp smtp send mail test function until a patch is available to prevent unauthorized email sending. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Missing Authorization

Weakness Enumeration

Related Identifiers

CVE-2024-9065

Affected Products

Wp Helper Premium