SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2023-6620

The POST SMTP Mailer WordPress plugin before 2.8.7 does not properly sanitise and escape several parameters before using them in SQL statements, leading to a SQL injection exploitable by high privilege users such as admin.

HIGH 7.2EPSS 14.1%

Does this matter?

EPSS puts the probability of exploitation in the next 30 days at 14.1%, higher than 96% of all known CVEs. Patch or mitigate before the next change window.

Description

The POST SMTP Mailer WordPress plugin before 2.8.7 does not properly sanitise and escape several parameters before using them in SQL statements, leading to a SQL injection exploitable by high privilege users such as admin.

CVSS 3.1
7.2 HIGHCVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
EPSS
14.06% probability · 96th percentile
CISA KEV
Not listed
Weakness
CWE-89
Affected
wpexperts/post smtp
Source
contact@wpscan.com

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.