CVE Vulnerabilities

CVE-2022-43504

Improper Authentication

Published: Dec 05, 2022 | Modified: Feb 03, 2023
CVSS 3.x
5.3
MEDIUM
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu

Improper authentication vulnerability in WordPress versions prior to 6.0.3 allows a remote unauthenticated attacker to obtain the email address of the user who posted a blog using the WordPress Post by Email Feature. The developer also provides new patched releases for all versions since 3.7.

Weakness

When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.

Affected Software

Name Vendor Start Version End Version
Wordpress Wordpress * 3.7.40 (excluding)
Wordpress Wordpress 3.8 (including) 3.8.40 (excluding)
Wordpress Wordpress 3.9 (including) 3.9.39 (excluding)
Wordpress Wordpress 4.0 (including) 4.0.37 (excluding)
Wordpress Wordpress 4.1 (including) 4.1.37 (excluding)
Wordpress Wordpress 4.2 (including) 4.2.34 (excluding)
Wordpress Wordpress 4.3 (including) 4.3.30 (excluding)
Wordpress Wordpress 4.4 (including) 4.4.29 (excluding)
Wordpress Wordpress 4.5 (including) 4.5.28 (excluding)
Wordpress Wordpress 4.6 (including) 4.6.25 (excluding)
Wordpress Wordpress 4.7 (including) 4.7.25 (excluding)
Wordpress Wordpress 4.8 (including) 4.8.21 (excluding)
Wordpress Wordpress 4.9 (including) 4.9.22 (excluding)
Wordpress Wordpress 5.0 (including) 5.0.18 (excluding)
Wordpress Wordpress 5.1 (including) 5.1.15 (excluding)
Wordpress Wordpress 5.2 (including) 5.2.17 (excluding)
Wordpress Wordpress 5.3 (including) 5.3.14 (excluding)
Wordpress Wordpress 5.4 (including) 5.4.12 (excluding)
Wordpress Wordpress 5.5 (including) 5.5.11 (excluding)
Wordpress Wordpress 5.6 (including) 5.6.10 (excluding)
Wordpress Wordpress 5.7 (including) 5.7.8 (excluding)
Wordpress Wordpress 5.8 (including) 5.8.6 (excluding)
Wordpress Wordpress 5.9 (including) 5.9.5 (excluding)
Wordpress Wordpress 6.0 (including) 6.0.3 (excluding)

Potential Mitigations

References