WordPress SendPress Newsletters plugin <= 1.23.11.6 - Broken Access Control vulnerability
CVE-2023-35040

5.3MEDIUM

Key Information:

Vendor
WordPress
Vendor
CVE Published:
14 June 2024

Summary

A missing authorization vulnerability in the SendPress Newsletters plugin may allow unauthorized users to access and manage sensitive information. Affected versions include any version up to 1.23.11.6. This flaw poses a significant risk as it enables potential attackers to manipulate newsletter settings or access sensitive data without proper authentication, compromising the integrity and confidentiality of user information.

Affected Version(s)

SendPress Newsletters <= 1.23.11.6

References

CVSS V3.1

Score:
5.3
Severity:
MEDIUM
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

Credit

Mika (Patchstack Alliance)
.