The Post SMTP Mailer/Email Log WordPress plugin before 2.1.7 does not have proper authorisation in some AJAX actions, which could allow high privilege users such as admin to perform blind SSRF on multisite installations for example.
History

Wed, 21 May 2025 20:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


cve-icon MITRE

Status: PUBLISHED

Assigner: WPScan

Published: 2022-09-26T12:35:32.000Z

Updated: 2025-05-21T19:21:14.244Z

Reserved: 2022-07-08T00:00:00.000Z

Link: CVE-2022-2352

cve-icon Vulnrichment

Updated: 2024-08-03T00:32:09.763Z

cve-icon NVD

Status : Modified

Published: 2022-09-26T13:15:10.320

Modified: 2025-05-21T20:15:26.560

Link: CVE-2022-2352

cve-icon Redhat

No data.