CVE Database /
CVE-2023-52233
CVE · High
CVE-2023-52233 — Post SMTP – Complete Email Deliverability and SMTP Solution with Email Logs, Alerts, Backup SMTP & Mobile App [post-smtp] < 2.8.7
| CVE |
Vulnerability |
Type |
Severity |
Affected |
Fixed in |
Published |
Status |
|
CVE-2023-52233
|
Post SMTP – Complete Email Deliverability and SMTP Solution with Email Logs, Alerts, Backup SMTP & Mobile App [post-smtp] < 2.8.7 |
Missing Authorization |
High
8.6
|
< 2.8.7
|
2.8.7 |
2024-01-05 |
—
|
CVE-2023-52233
The Post SMTP Mailer/Email Log plugin for WordPress contained a broken access control vulnerability prior to version 2.8.7 that allowed unauthenticated or low-privileged users to perform administrative actions due to missing authorization and nonce verification checks. This flaw, discovered by Yuchen Ji, could be exploited by attackers to execute functions normally restricted to higher-privileged users. Users should upgrade to version 2.8.7 or later to remediate this issue.
Based on public CVE data (MITRE/NVD).
Scan your WordPress site free
No signup, no credit card — enter your URL and get a security report in seconds.
See the full security page for this plugin
Browse the CVE database
Browse all security findings