CVE-2023-5644: WP Mail Log < 1.1.3 – Incorrect Authorization in REST API Endpoints
Published Dec 26, 2023
·Updated
The WP Mail Log WordPress plugin before 1.1.3 does not correctly authorize its REST API endpoints, allowing users with the Contributor role to view and delete data that should only be accessible to Admin users.
Affected Software
1 affected component
WPVibes Wp Mail Log Wordpress<1.1.3
Event History
Dec 26, 2023
CVE Published
via MITRE·06:33 PM
Data Sourced
via MITRE·06:33 PM
DescriptionWeakness
May 24, 57290
Event
via FIRST·01:26 AM
Frequently Asked Questions
1
What is the severity of CVE-2023-5644?
CVE-2023-5644 has a medium severity rating due to improper authorization in the WP Mail Log plugin.
2
How do I fix CVE-2023-5644?
To fix CVE-2023-5644, update the WP Mail Log plugin to version 1.1.3 or later.
3
Who is affected by CVE-2023-5644?
Users with the Contributor role are affected by CVE-2023-5644 as they gain unauthorized access to sensitive data.
4
What are the consequences of CVE-2023-5644?
The consequences of CVE-2023-5644 include potential data exposure and manipulation by unauthorized users.
5
Is CVE-2023-5644 being actively exploited?
There is no indication that CVE-2023-5644 is currently being actively exploited, but it is recommended to mitigate the risk promptly.