Unauthenticated Email Relay Vulnerability in Super Store Finder Plugin for WordPress
CVE-2023-5054
5.8MEDIUM
Summary
The Super Store Finder plugin for WordPress is vulnerable due to inadequate restrictions on the sendMail.php file, which permits unauthorized access. This flaw enables attackers to exploit the site's server for sending emails with arbitrary content. The vulnerability affects all versions up to and including 6.9.3. The publicly disclosed nature of this vulnerability and known exploits necessitate immediate attention to secure the affected systems.
Affected Version(s)
Super Store Finder * <= 6.9.3
References
CVSS V3.1
Score:
5.8
Severity:
MEDIUM
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Changed
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Etharus