CVE Vulnerabilities

CVE-2022-43504

Improper Authentication

Published: Dec 05, 2022 | Modified: Apr 24, 2025
CVSS 3.x
5.3
MEDIUM
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu
LOW
root.io logo minimus.io logo echo.ai logo

Improper authentication vulnerability in WordPress versions prior to 6.0.3 allows a remote unauthenticated attacker to obtain the email address of the user who posted a blog using the WordPress Post by Email Feature. The developer also provides new patched releases for all versions since 3.7.

Weakness

When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.

Affected Software

NameVendorStart VersionEnd Version
WordpressWordpress*3.7.40 (excluding)
WordpressWordpress3.8 (including)3.8.40 (excluding)
WordpressWordpress3.9 (including)3.9.39 (excluding)
WordpressWordpress4.0 (including)4.0.37 (excluding)
WordpressWordpress4.1 (including)4.1.37 (excluding)
WordpressWordpress4.2 (including)4.2.34 (excluding)
WordpressWordpress4.3 (including)4.3.30 (excluding)
WordpressWordpress4.4 (including)4.4.29 (excluding)
WordpressWordpress4.5 (including)4.5.28 (excluding)
WordpressWordpress4.6 (including)4.6.25 (excluding)
WordpressWordpress4.7 (including)4.7.25 (excluding)
WordpressWordpress4.8 (including)4.8.21 (excluding)
WordpressWordpress4.9 (including)4.9.22 (excluding)
WordpressWordpress5.0 (including)5.0.18 (excluding)
WordpressWordpress5.1 (including)5.1.15 (excluding)
WordpressWordpress5.2 (including)5.2.17 (excluding)
WordpressWordpress5.3 (including)5.3.14 (excluding)
WordpressWordpress5.4 (including)5.4.12 (excluding)
WordpressWordpress5.5 (including)5.5.11 (excluding)
WordpressWordpress5.6 (including)5.6.10 (excluding)
WordpressWordpress5.7 (including)5.7.8 (excluding)
WordpressWordpress5.8 (including)5.8.6 (excluding)
WordpressWordpress5.9 (including)5.9.5 (excluding)
WordpressWordpress6.0 (including)6.0.3 (excluding)
WordpressUbuntubionic*
WordpressUbuntufocal*
WordpressUbuntukinetic*
WordpressUbuntulunar*
WordpressUbuntumantic*
WordpressUbuntuoracular*
WordpressUbuntuplucky*
WordpressUbuntutrusty*
WordpressUbuntuxenial*

Potential Mitigations

References