CVE-2023-3213: WP Mail SMTP Pro <= 3.8.0 - Missing Authorization to Information Dislcosure via is_print_page
The WP Mail SMTP Pro plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the isprintpage function in versions up to, and including, 3.8.0. This makes it possible for unauthenticated attackers to disclose potentially sensitive email information.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2023-3213?
CVE-2023-3213 is a vulnerability in the WP Mail SMTP Pro plugin for WordPress that allows unauthorized access of data.
What is the severity of CVE-2023-3213?
The severity of CVE-2023-3213 is medium with a CVSS score of 5.3.
How does CVE-2023-3213 affect the WP Mail SMTP Pro plugin for WordPress?
CVE-2023-3213 affects the WP Mail SMTP Pro plugin for WordPress by allowing unauthenticated attackers to disclose potentially sensitive email information.
How can I fix CVE-2023-3213?
To fix CVE-2023-3213, update the WP Mail SMTP Pro plugin for WordPress to version 3.8.1 or higher.
Where can I find more information about CVE-2023-3213?
You can find more information about CVE-2023-3213 at the following references: [Link 1](https://wpmailsmtp.com/docs/how-to-view-recent-changes-to-the-wp-mail-smtp-plugin-changelog/) and [Link 2](https://www.wordfence.com/threat-intel/vulnerabilities/id/a813251b-a4c1-4b23-ad03-dcc1f4f19eb9?source=cve).