PT-2023-23634 · WordPress · Wp Mail Smtp Pro
CVSS v3.1
5.3
Média
| Vetor | AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
WP Mail SMTP Pro plugin for WordPress versions up to, and including, 3.8.0
Description
The issue is related to a missing capability check on the
is print page function, which allows unauthorized access to data. This makes it possible for unauthenticated attackers to disclose potentially sensitive email information.Recommendations
For WP Mail SMTP Pro plugin for WordPress versions up to, and including, 3.8.0, update to a version higher than 3.8.0 to resolve the issue. As a temporary workaround, consider restricting access to the
is print page function until a patch is available.Correção
Missing Authorization
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Wp Mail Smtp Pro