Unauthenticated Hook Injection Vulnerability in Email Log Plugin for WordPress
CVE-2024-0867
8.1HIGH
Summary
The Email Log plugin for WordPress is exposed to a vulnerability characterized by unauthenticated hook injection, affecting all versions up to and including 2.4.8. This flaw exists due to the exploitation of the check_nonce function, allowing attackers without authentication to potentially execute specific actions leveraging hooks within WordPress. For successful exploitation, the attacker must possess knowledge of the nonce associated with the desired action, compounded by the lack of a capability check in the plugin’s functionality, significantly increasing the risk of unauthorized actions.
Affected Version(s)
Email Log * <= 2.4.8
References
CVSS V3.1
Score:
8.1
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Sean Murphy