PT-2026-64914 · WordPress · Wp Page Builder
CVSS v3.1
9.8
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
SP Page Builder versions prior to 6.7.1
Description
A hardcoded, product-wide secret allows unauthenticated attackers to perform mail relay by forging the mail from address of forms.
Recommendations
Update SP Page Builder to version 6.7.1 or later.
Fix
Using Hardcoded Credentials
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Wp Page Builder