Sploitus

CVE-2022-2370

1 known exploit for CVE-2022-2370

The YaySMTP WordPress plugin before 2.2.1 does not have capability check before displaying the Mailer Credentials in JS code for the settings, allowing any authenticated users, such as subscriber to retrieve them

Affected products
Yaysmtp
Yaycommerce Yaysmtp
< 2.2.1
Fix
Available
CVSS 3.1
6.5 MEDIUM
EPSS
0.9% (57th percentile)
Weakness
CWE-862
NVD status
Modified
Published
2022-08-01
CVE-2022-2370 at NVD
Authoritative description, scoring and affected products

1 known exploit for CVE-2022-2370

Proof-of-concept code and exploit modules indexed by Sploitus