CVE-2022-2369
The YaySMTP WordPress plugin before 2.2.1 does not have capability check in an AJAX action, allowing any logged in users, such as subscriber to view the Logs of the plugin
- Affected products
- Yaysmtp
- Yaycommerce Yaysmtp
- < 2.2.1
- Fix
- Available
- CVSS 3.1
- 4.3 MEDIUM
- EPSS
- 0.7% (51th percentile)
- Weakness
- CWE-862
- NVD status
- Modified
- Published
- 2022-08-01
CVE-2022-2369 at NVD
1 known exploit for CVE-2022-2369
Proof-of-concept code and exploit modules indexed by Sploitus