CVE-2022-2352: Post SMTP < 2.1.7 - Admin+ Blind SSRF
The Post SMTP Mailer/Email Log WordPress plugin before 2.1.7 does not have proper authorisation in some AJAX actions, which could allow high privilege users such as admin to perform blind SSRF on multisite installations for example.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the vulnerability ID for this issue?
The vulnerability ID for this issue is CVE-2022-2352.
What is the severity of CVE-2022-2352?
The severity of CVE-2022-2352 is high with a score of 7.2.
What is the affected software for CVE-2022-2352?
The affected software for CVE-2022-2352 is the Post SMTP Mailer/Email Log WordPress plugin before version 2.1.7.
What is the description of CVE-2022-2352?
The Post SMTP Mailer/Email Log WordPress plugin before version 2.1.7 does not have proper authorization in some AJAX actions, which could allow high privilege users such as admin to perform blind SSRF on multisite installations.
How can I fix CVE-2022-2352?
To fix CVE-2022-2352, update the Post SMTP Mailer/Email Log WordPress plugin to version 2.1.7 or later.