Impact
The vulnerability is a Missing Authorization flaw in the Ultimate WP Mail plugin for WordPress, allowing an attacker to bypass authentication controls and access the email log feature. The flaw could enable reading of log entries that may contain sensitive information such as user emails or session identifiers. It is inferred that this information could be used for account takeover or social engineering attacks. This weakness is classified as CWE-862: Missing Authorization.
Affected Systems
Rustaurius Ultimate WP Mail, a WordPress plugin, is affected in all releases from the earliest available version through legacy versions up to and including 1.3.5. Administrators using the plugin should verify their installed version and consider upgrading or replacing it if a fixed version is available beyond 1.3.5.
Risk and Exploitability
The flaw carries a CVSS score of 8.8, indicating high severity, while the EPSS score is less than 1%, suggesting a very low but nonzero likelihood of exploitation. It is not listed in CISA’s KEV catalog, so no publicly known exploits have been reported to date. It is inferred that, because the vulnerability stems from an absence of access control on the email log endpoint, an attacker could send unauthenticated HTTP requests to retrieve sensitive log data, which could then be exploited for account takeover or phishing campaigns.
OpenCVE Enrichment
EUVD