Unauthorized Access Vulnerability in WP Extra Plugin for WordPress
CVE-2023-5314
4.3MEDIUM
What is CVE-2023-5314?
The WP Extra plugin for WordPress contains a vulnerability that enables authenticated attackers, even with minimal permissions such as a subscriber role, to bypass necessary capability checks within the 'test-email' functionality of the register() method. This security flaw can lead to the exploitation of the site's mail server, allowing malicious users to send emails with arbitrary content to any destination, potentially resulting in spam or phishing attacks.
Affected Version(s)
WP EXtra * <= 6.2