Unauthenticated Hook Injection Vulnerability in Email Log Plugin for WordPress
CVE-2024-0867

8.1HIGH

Key Information:

Vendor
Wordpress
Status
Vendor
CVE Published:
24 May 2024

Summary

The Email Log plugin for WordPress is exposed to a vulnerability characterized by unauthenticated hook injection, affecting all versions up to and including 2.4.8. This flaw exists due to the exploitation of the check_nonce function, allowing attackers without authentication to potentially execute specific actions leveraging hooks within WordPress. For successful exploitation, the attacker must possess knowledge of the nonce associated with the desired action, compounded by the lack of a capability check in the plugin’s functionality, significantly increasing the risk of unauthorized actions.

Affected Version(s)

Email Log * <= 2.4.8

References

CVSS V3.1

Score:
8.1
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Sean Murphy
.