The WP Helper Premium plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'whp_smtp_send_mail_test' function in all versions up to, and including, 4.6.1. This makes it possible for unauthenticated attackers to send emails containing any content and originating from the vulnerable WordPress instance to any recipient.
Metrics
Affected Vendors & Products
References
History
Tue, 15 Oct 2024 14:30:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Matbao
Matbao wp Helper Premium |
|
CPEs | cpe:2.3:a:matbao:wp_helper_premium:*:*:*:*:*:wordpress:*:* | |
Vendors & Products |
Matbao
Matbao wp Helper Premium |
Fri, 11 Oct 2024 21:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|
Thu, 10 Oct 2024 02:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | The WP Helper Premium plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'whp_smtp_send_mail_test' function in all versions up to, and including, 4.6.1. This makes it possible for unauthenticated attackers to send emails containing any content and originating from the vulnerable WordPress instance to any recipient. | |
Title | WP Helper Premium <= 4.6.1 - Missing Authorization in whp_smtp_send_mail_test | |
Weaknesses | CWE-862 | |
References |
| |
Metrics |
cvssV3_1
|
MITRE
Status: PUBLISHED
Assigner: Wordfence
Published: 2024-10-10T02:06:08.162Z
Updated: 2024-10-10T17:38:07.505Z
Reserved: 2024-09-20T22:12:14.639Z
Link: CVE-2024-9065
Vulnrichment
Updated: 2024-10-10T17:38:02.216Z
NVD
Status : Analyzed
Published: 2024-10-10T02:15:04.363
Modified: 2024-10-15T14:14:18.590
Link: CVE-2024-9065
Redhat
No data.