WordPress Plugin Vulnerabilities

Coming soon and Maintenance mode < 3.6.8 - Arbitrary Email Sending to Subscribed Users via CSRF

Description

The plugin does not have CSRF check in its coming_soon_send_mail AJAX action, allowing attackers to make logged in admin to send arbitrary emails to all subscribed users via a CSRF attack

Proof of Concept

Affects Plugins

Fixed in 3.6.8

References

Classification

Miscellaneous

Original Researcher
Krzysztof Zając
Submitter
Krzysztof Zając
Submitter website
Verified
Yes

Timeline

Publicly Published
2022-01-24 (about 3 years ago)
Added
2022-01-24 (about 3 years ago)
Last Updated
2022-04-12 (about 3 years ago)

Other