Unauthenticated Email Relay Vulnerability in Super Store Finder Plugin for WordPress
CVE-2023-5054

5.8MEDIUM

Key Information:

Vendor
WordPress
Vendor
CVE Published:
19 September 2023

Summary

The Super Store Finder plugin for WordPress is vulnerable due to inadequate restrictions on the sendMail.php file, which permits unauthorized access. This flaw enables attackers to exploit the site's server for sending emails with arbitrary content. The vulnerability affects all versions up to and including 6.9.3. The publicly disclosed nature of this vulnerability and known exploits necessitate immediate attention to secure the affected systems.

Affected Version(s)

Super Store Finder * <= 6.9.3

References

CVSS V3.1

Score:
5.8
Severity:
MEDIUM
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Etharus
.