Vulnerability Description
The Revision Manager TMC plugin for WordPress is vulnerable to unauthorized arbitrary email sending due to a missing capability check on the _a_ajaxQuickEmailTestCallback() function in all versions up to, and including, 2.8.19. This makes it possible for authenticated attackers, with subscriber-level access and above, to send emails with arbitrary content to any individual through the vulnerable web server.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Jetplugs | Revision Manager Tmc | < 2.8.20 |
Related Weaknesses (CWE)
References
- https://plugins.trac.wordpress.org/browser/revision-manager-tmc/trunk/src/ComponProduct
- https://plugins.trac.wordpress.org/changeset/3147298/Patch
- https://www.wordfence.com/threat-intel/vulnerabilities/id/2c8a6ff9-6aa8-4e0f-b05Third Party Advisory
FAQ
What is CVE-2024-7622?
CVE-2024-7622 is a vulnerability with a CVSS score of 4.3 (MEDIUM). The Revision Manager TMC plugin for WordPress is vulnerable to unauthorized arbitrary email sending due to a missing capability check on the _a_ajaxQuickEmailTestCallback() function in all versions up...
How severe is CVE-2024-7622?
CVE-2024-7622 has been rated MEDIUM with a CVSS base score of 4.3/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2024-7622?
Check the references section above for vendor advisories and patch information. Affected products include: Jetplugs Revision Manager Tmc.