CVE · Low

CVE-2023-1430 — FluentCRM – Email Newsletter, Automation, Email Marketing, Email Campaigns, Optins, Leads, and CRM Solution [fluent-crm] < 2.8.02

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2023-1430 FluentCRM – Email Newsletter, Automation, Email Marketing, Email Campaigns, Optins, Leads, and CRM Solution [fluent-crm] < 2.8.02 Use of a One-Way Hash without a Salt Low 3.7 < 2.8.02 2.8.02 2023-06-01

CVE-2023-1430

The FluentCRM plugin for WordPress before version 2.8.02 contains a vulnerability that allows unauthenticated attackers to modify subscription data without proper authorization. The flaw stems from using unsalted MD5 hashing to protect subscription controls, which can be bypassed if an attacker knows a subscriber's email address. This vulnerability enables attackers to unsubscribe users from mailing lists and alter their subscription preferences without authentication credentials.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.