CVE-2022-0164: Coming soon and Maintenance mode < 3.6.7 - Subscriber+ Arbitrary Email Sending to Subscribed Users
The Coming soon and Maintenance mode WordPress plugin before 3.5.3 does not have authorisation and CSRF checks in its comingsoonsendmail AJAX action, allowing any authenticated users, with a role as low as subscriber to send arbitrary emails to all subscribed users
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is CVE-2022-0164?
CVE-2022-0164 is a vulnerability in the Coming soon and Maintenance mode WordPress plugin that allows authenticated users to send arbitrary emails to all subscribed users.
What is the severity of CVE-2022-0164?
CVE-2022-0164 has a severity level of medium, with a severity value of 4.3.
How does CVE-2022-0164 affect the Coming soon and Maintenance mode WordPress plugin?
CVE-2022-0164 affects the Coming soon and Maintenance mode WordPress plugin version up to and exclusive to 3.5.3.
Are there any fixes or patches available for CVE-2022-0164?
Yes, a fix for CVE-2022-0164 is available in version 3.5.3 of the Coming soon and Maintenance mode WordPress plugin.
Where can I find more information about CVE-2022-0164?
You can find more information about CVE-2022-0164 at the following references: [Reference 1](https://plugins.trac.wordpress.org/changeset/2655973), [Reference 2](https://wpscan.com/vulnerability/942535f9-73bf-4467-872a-20075f03bc51).