CVE-2023-6042: Getwid < 2.0.3 - Unauthenticated Arbitrary Email Sending to Admin
Published Jan 8, 2024
·Updated
Any unauthenticated user may send e-mail from the site with any title or content to the admin
Affected Software
1 affected component
MotoPress Getwid Wordpress<2.0.3
Event History
Jan 8, 2024
CVE Published
via MITRE·07:00 PM
Data Sourced
via MITRE·07:00 PM
DescriptionWeakness
Data Sourced
via NVD·07:15 PM
DescriptionSeverityAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2023-6042?
CVE-2023-6042 is a high-severity vulnerability that allows unauthenticated users to send arbitrary emails from the site.
2
How do I fix CVE-2023-6042?
To mitigate CVE-2023-6042, update the Motopress Getwid plugin to version 2.0.3 or later.
3
What systems are affected by CVE-2023-6042?
CVE-2023-6042 affects versions of Motopress Getwid plugin for WordPress up to 2.0.3.
4
Can CVE-2023-6042 be exploited remotely?
Yes, CVE-2023-6042 can be exploited remotely by any unauthenticated user.
5
What impact does CVE-2023-6042 have on a WordPress site?
CVE-2023-6042 allows attackers to send spam emails posing as the site admin, potentially damaging the site's credibility.