CVE-2022-2370
The YaySMTP WordPress plugin before 2.2.1 does not have capability check before displaying the Mailer Credentials in JS code for the settings, allowing any authenticated users, such as subscriber to retrieve them
- Affected products
- Yaysmtp
- Yaycommerce Yaysmtp
- < 2.2.1
- Fix
- Available
- CVSS 3.1
- 6.5 MEDIUM
- EPSS
- 0.9% (57th percentile)
- Weakness
- CWE-862
- NVD status
- Modified
- Published
- 2022-08-01
CVE-2022-2370 at NVD
1 known exploit for CVE-2022-2370
Proof-of-concept code and exploit modules indexed by Sploitus