CVE · Medium

CVE-2023-6496 — Manage Notification E-mails [manage-notification-emails] < 1.8.6

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2023-6496 Manage Notification E-mails [manage-notification-emails] < 1.8.6 Improper Authorization Medium 5.3 < 1.8.6 1.8.6 2023-12-08

CVE-2023-6496

The Manage Notification E-mails plugin for WordPress contained an authorization bypass flaw in versions 1.8.5 and earlier through the card_famne_export_settings function, allowing attackers without valid credentials to access and retrieve sensitive plugin configuration data. An update to version 1.8.6 or later resolves this vulnerability.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.