First published: Mon Feb 21 2022(Updated: )
The Coming soon and Maintenance mode WordPress plugin before 3.6.8 does not have CSRF check in its coming_soon_send_mail AJAX action, allowing attackers to make logged in admin to send arbitrary emails to all subscribed users via a CSRF attack
Credit: contact@wpscan.com
Affected Software | Affected Version | How to fix |
---|---|---|
Wpdevart Coming Soon And Maintenance Mode | <3.6.8 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2022-0199 is a vulnerability in the Coming soon and Maintenance mode WordPress plugin before version 3.6.8 that allows attackers to make logged in admin users send arbitrary emails to all subscribed users via a CSRF attack.
CVE-2022-0199 has a severity score of 4.3, which is considered medium.
The affected software is the Coming soon and Maintenance mode WordPress plugin before version 3.6.8.
An attacker can exploit CVE-2022-0199 by performing a CSRF attack to make a logged in admin user send arbitrary emails to all subscribed users.
Yes, the fix for CVE-2022-0199 is to update the Coming soon and Maintenance mode WordPress plugin to version 3.6.8 or later.