Unauthorized Email Modification Vulnerability Affects WP Helper Premium Plugin
CVE-2024-9065
What is CVE-2024-9065?
The WP Helper Premium plugin for WordPress contains a vulnerability that permits unauthorized data modification due to a lack of capability checks on the 'whp_smtp_send_mail_test' function. This issue affects all versions up to and including 4.6.1. The absence of proper security measures allows unauthenticated attackers to leverage this vulnerability to send arbitrary emails containing any content. These emails appear to originate from the compromised WordPress instance, potentially misleading recipients and facilitating further attacks.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
WP Helper Premium * <= 4.6.1
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved