CVE Database /
CVE-2023-1430
CVE · Low
CVE-2023-1430 — FluentCRM – Email Newsletter, Automation, Email Marketing, Email Campaigns, Optins, Leads, and CRM Solution [fluent-crm] < 2.8.02
| CVE |
Vulnerability |
Type |
Severity |
Affected |
Fixed in |
Published |
Status |
|
CVE-2023-1430
|
FluentCRM – Email Newsletter, Automation, Email Marketing, Email Campaigns, Optins, Leads, and CRM Solution [fluent-crm] < 2.8.02 |
Use of a One-Way Hash without a Salt |
Low
3.7
|
< 2.8.02
|
2.8.02 |
2023-06-01 |
—
|
CVE-2023-1430
The FluentCRM plugin for WordPress before version 2.8.02 contains a vulnerability that allows unauthenticated attackers to modify subscription data without proper authorization. The flaw stems from using unsalted MD5 hashing to protect subscription controls, which can be bypassed if an attacker knows a subscriber's email address. This vulnerability enables attackers to unsubscribe users from mailing lists and alter their subscription preferences without authentication credentials.
Based on public CVE data (MITRE/NVD).
Scan your WordPress site free
No signup, no credit card — enter your URL and get a security report in seconds.
See the full security page for this plugin
Browse the CVE database
Browse all security findings