CVE-2022-0199: Coming soon and Maintenance mode < 3.6.8 - Arbitrary Email Sending to Subscribed Users via CSRF
The Coming soon and Maintenance mode WordPress plugin before 3.6.8 does not have CSRF check in its comingsoonsendmail AJAX action, allowing attackers to make logged in admin to send arbitrary emails to all subscribed users via a CSRF attack
Affected Software
Event History
Frequently Asked Questions
What is CVE-2022-0199?
CVE-2022-0199 is a vulnerability in the Coming soon and Maintenance mode WordPress plugin before version 3.6.8 that allows attackers to make logged in admin users send arbitrary emails to all subscribed users via a CSRF attack.
How severe is CVE-2022-0199?
CVE-2022-0199 has a severity score of 4.3, which is considered medium.
What is the affected software for CVE-2022-0199?
The affected software is the Coming soon and Maintenance mode WordPress plugin before version 3.6.8.
How can an attacker exploit CVE-2022-0199?
An attacker can exploit CVE-2022-0199 by performing a CSRF attack to make a logged in admin user send arbitrary emails to all subscribed users.
Is there a fix for CVE-2022-0199?
Yes, the fix for CVE-2022-0199 is to update the Coming soon and Maintenance mode WordPress plugin to version 3.6.8 or later.