CVE Vulnerabilities

CVE-2023-5314

Published: Nov 22, 2023 | Modified: Nov 27, 2023
CVSS 3.x
4.3
MEDIUM
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu

The WP EXtra plugin for WordPress is vulnerable to unauthorized access to restricted functionality due to a missing capability check on the test-email section of the register() function in versions up to, and including, 6.2. This makes it possible for authenticated attackers, with minimal permissions such as a subscriber, to send emails with arbitrary content to arbitrary locations from the affected sites mail server.

Affected Software

Name Vendor Start Version End Version
Wp_extra Wpvnteam * 6.2 (including)

References