CVE-2023-1430: FluentCRM - Marketing Automation For WordPress <= 2.8.01 - Insufficient Use of Hash as Authorization Control
The FluentCRM - Marketing Automation For WordPress plugin for WordPress is vulnerable to unauthorized modification of data in versions up to, and including, 2.7.40 due to the use of an MD5 hash without a salt to control subscriptions. This makes it possible for unauthenticated attackers to unsubscribe users from lists and manage subscriptions, granted they gain access to any targeted subscribers email address.
Other sources
The FluentCRM - Marketing Automation For WordPress plugin for WordPress is vulnerable to unauthorized modification of data in versions up to, and including, 2.8.01 due to the use of an MD5 hash without a salt to control subscriptions. This makes it possible for unauthenticated attackers to unsubscribe users from lists and manage subscriptions, granted they gain access to any targeted subscribers email address.
— MITRE
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the vulnerability ID for this vulnerability?
The vulnerability ID for this vulnerability is CVE-2023-1430.
What is the severity of CVE-2023-1430?
The severity of CVE-2023-1430 is medium with a severity value of 3.7.
What is the affected software for CVE-2023-1430?
The affected software for CVE-2023-1430 is the FluentCRM - Marketing Automation For WordPress plugin for WordPress versions up to, and including, 2.7.40.
How is the vulnerability exploited in CVE-2023-1430?
The vulnerability in CVE-2023-1430 allows unauthenticated attackers to unauthorized modify data by exploiting the use of an MD5 hash without a salt to control subscriptions.
Are there any references for CVE-2023-1430?
Yes, you can find references for CVE-2023-1430 at the following links: [Link 1](https://plugins.trac.wordpress.org/changeset/2899218/fluent-crm/tags/2.8.0/app/Hooks/Handlers/ExternalPages.php?old=2873074&old_path=fluent-crm%2Ftags%2F2.7.40%2Fapp%2FHooks%2FHandlers%2FExternalPages.php), [Link 2](https://www.wordfence.com/threat-intel/vulnerabilities/id/de6da87e-8f7d-4120-8a1b-390ef7733d84?source=cve).