The POST SMTP Mailer WordPress plugin before 2.5.7 does not have proper CSRF checks in some AJAX actions, which could allow attackers to make logged in users with the manage_postman_smtp capability delete arbitrary logs via a CSRF attack.
History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: WPScan

Published: 2024-01-16T15:55:29.719Z

Updated: 2024-08-02T06:48:07.773Z

Reserved: 2023-06-09T08:24:52.036Z

Link: CVE-2023-3178

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Analyzed

Published: 2024-01-16T16:15:11.243

Modified: 2024-01-22T19:43:34.693

Link: CVE-2023-3178

cve-icon Redhat

No data.