CVE-2022-1630

Severity
6.5MEDIUM
EPSS
0.1%
top 65.90%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJun 20
Latest updateJun 21

Description

The WP-EMail WordPress plugin before 2.69.0 does not protect its log deletion functionality with nonce checks, allowing attacker to make a logged in admin delete logs via a CSRF attack

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:NExploitability: 2.8 | Impact: 3.6

Affected Packages2 packages

CVEListV5unknown/wp-email2.69.02.69.0

🔴Vulnerability Details

2
GHSA
GHSA-vg5f-hrqf-wrmv: The WP-EMail WordPress plugin before 22022-06-21
CVEList
WP-Email < 2.69.0 - Log Deletion via CSRF2022-06-20
CVE-2022-1630 (MEDIUM CVSS 6.5) | The WP-EMail WordPress plugin befor | cvebase.io