Unauthenticated Hook Injection Vulnerability in Email Log Plugin for WordPress
CVE-2024-0867
8.1HIGH
What is CVE-2024-0867?
The Email Log plugin for WordPress is exposed to a vulnerability characterized by unauthenticated hook injection, affecting all versions up to and including 2.4.8. This flaw exists due to the exploitation of the check_nonce function, allowing attackers without authentication to potentially execute specific actions leveraging hooks within WordPress. For successful exploitation, the attacker must possess knowledge of the nonce associated with the desired action, compounded by the lack of a capability check in the plugin’s functionality, significantly increasing the risk of unauthorized actions.
Affected Version(s)
Email Log * <= 2.4.8