PT-2024-12287 · WordPress · Post Smtp Mailer

·

CVE-2023-3178

·

Published

2024-01-16

·

Updated

2024-01-22

CVSS v3.1

4.3

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N
Name of the Vulnerable Software and Affected Versions POST SMTP Mailer WordPress plugin versions prior to 2.5.7
Description The issue is related to improper CSRF checks in some AJAX actions. This could allow attackers to make logged-in users with the manage postman smtp capability delete arbitrary logs via a CSRF attack.
Recommendations For versions prior to 2.5.7, update to version 2.5.7 or later to resolve the issue. As a temporary workaround, consider restricting access to the AJAX actions that are vulnerable to CSRF attacks until a patch is applied.

Exploit

Fix

CSRF

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2023-3178

Affected Products

Post Smtp Mailer