WordPress SendPress Newsletters plugin <= 1.23.11.6 - Broken Access Control vulnerability
CVE-2023-35040
5.3MEDIUM
Summary
A missing authorization vulnerability in the SendPress Newsletters plugin may allow unauthorized users to access and manage sensitive information. Affected versions include any version up to 1.23.11.6. This flaw poses a significant risk as it enables potential attackers to manipulate newsletter settings or access sensitive data without proper authentication, compromising the integrity and confidentiality of user information.
Affected Version(s)
SendPress Newsletters <= 1.23.11.6
References
CVSS V3.1
Score:
5.3
Severity:
MEDIUM
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Credit
Mika (Patchstack Alliance)