Vulnerability Description
The YaySMTP WordPress plugin before 2.2.1 does not have capability check in an AJAX action, allowing any logged in users, such as subscriber to view the Logs of the plugin
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Yaycommerce | Yaysmtp | < 2.2.1 |
Related Weaknesses (CWE)
References
- https://wpscan.com/vulnerability/9ec8d318-9d25-4868-94c6-7c16444c275dExploitThird Party Advisory
- https://wpscan.com/vulnerability/9ec8d318-9d25-4868-94c6-7c16444c275dExploitThird Party Advisory
FAQ
What is CVE-2022-2369?
CVE-2022-2369 is a vulnerability with a CVSS score of 4.3 (MEDIUM). The YaySMTP WordPress plugin before 2.2.1 does not have capability check in an AJAX action, allowing any logged in users, such as subscriber to view the Logs of the plugin
How severe is CVE-2022-2369?
CVE-2022-2369 has been rated MEDIUM with a CVSS base score of 4.3/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2022-2369?
Check the references section above for vendor advisories and patch information. Affected products include: Yaycommerce Yaysmtp.