First published: Mon Sep 26 2022(Updated: )
The Post SMTP Mailer/Email Log WordPress plugin before 2.1.7 does not have proper authorisation in some AJAX actions, which could allow high privilege users such as admin to perform blind SSRF on multisite installations for example.
Credit: contact@wpscan.com
Affected Software | Affected Version | How to fix |
---|---|---|
Wpexperts Post SMTP | <2.1.7 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID for this issue is CVE-2022-2352.
The severity of CVE-2022-2352 is high with a score of 7.2.
The affected software for CVE-2022-2352 is the Post SMTP Mailer/Email Log WordPress plugin before version 2.1.7.
The Post SMTP Mailer/Email Log WordPress plugin before version 2.1.7 does not have proper authorization in some AJAX actions, which could allow high privilege users such as admin to perform blind SSRF on multisite installations.
To fix CVE-2022-2352, update the Post SMTP Mailer/Email Log WordPress plugin to version 2.1.7 or later.