CVE-2022-2370: YaySMTP < 2.2.1 - Subscriber+ SMTP Credentials Leak
Published Aug 1, 2022
·Updated
The YaySMTP WordPress plugin before 2.2.1 does not have capability check before displaying the Mailer Credentials in JS code for the settings, allowing any authenticated users, such as subscriber to retrieve them
Affected Software
1 affected component
Yaycommerce Yaysmtp Wordpress<2.2.1
Event History
Aug 1, 2022
CVE Published
via MITRE·12:52 PM
Data Sourced
via MITRE·12:52 PM
DescriptionWeakness
Frequently Asked Questions
1
What is the severity of CVE-2022-2370?
The severity of CVE-2022-2370 is classified as a medium risk due to the exposure of sensitive data.
2
How do I fix CVE-2022-2370?
To fix CVE-2022-2370, update the YaySMTP WordPress plugin to version 2.2.1 or higher.
3
Who is affected by CVE-2022-2370?
Any authenticated user, including subscribers, can be affected by CVE-2022-2370 as it allows them to access Mailer Credentials.
4
What are the consequences of CVE-2022-2370?
The consequences of CVE-2022-2370 include potential unauthorized access to sensitive email configuration data.
5
Is there a patch for CVE-2022-2370?
Yes, a patch is available in the form of an update to YaySMTP plugin version 2.2.1.