The Revision Manager TMC plugin for WordPress is vulnerable to unauthorized arbitrary email sending due to a missing capability check on the _a_ajaxQuickEmailTestCallback() function in all versions up to, and including, 2.8.19. This makes it possible for authenticated attackers, with subscriber-level access and above, to send emails with arbitrary content to any individual through the vulnerable web server.
Advisories
Source ID Title
EUVD EUVD EUVD-2024-48513 The Revision Manager TMC plugin for WordPress is vulnerable to unauthorized arbitrary email sending due to a missing capability check on the _a_ajaxQuickEmailTestCallback() function in all versions up to, and including, 2.8.19. This makes it possible for authenticated attackers, with subscriber-level access and above, to send emails with arbitrary content to any individual through the vulnerable web server.
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Thu, 26 Sep 2024 22:00:00 +0000

Type Values Removed Values Added
First Time appeared Jetplugs
Jetplugs revision Manager Tmc
CPEs cpe:2.3:a:jetplugs:revision_manager_tmc:*:*:*:*:*:wordpress:*:*
Vendors & Products Jetplugs
Jetplugs revision Manager Tmc

Fri, 06 Sep 2024 15:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 06 Sep 2024 14:00:00 +0000

Type Values Removed Values Added
Description The Revision Manager TMC plugin for WordPress is vulnerable to unauthorized arbitrary email sending due to a missing capability check on the _a_ajaxQuickEmailTestCallback() function in all versions up to, and including, 2.8.19. This makes it possible for authenticated attackers, with subscriber-level access and above, to send emails with arbitrary content to any individual through the vulnerable web server.
Title Revision Manager TMC <= 2.8.19 - Missing Authorization to Authenticated (Subscriber+) Arbitrary Email Sending
Weaknesses CWE-862
References
Metrics cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: Wordfence

Published:

Updated: 2024-09-06T14:12:41.701Z

Reserved: 2024-08-08T17:42:09.428Z

Link: CVE-2024-7622

cve-icon Vulnrichment

Updated: 2024-09-06T14:12:33.995Z

cve-icon NVD

Status : Analyzed

Published: 2024-09-06T14:15:13.553

Modified: 2024-09-26T21:42:15.400

Link: CVE-2024-7622

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.