The Revision Manager TMC plugin for WordPress is vulnerable to unauthorized arbitrary email sending due to a missing capability check on the _a_ajaxQuickEmailTestCallback() function in all versions up to, and including, 2.8.19. This makes it possible for authenticated attackers, with subscriber-level access and above, to send emails with arbitrary content to any individual through the vulnerable web server.
References
Configurations
History
26 Sep 2024, 21:42
Type | Values Removed | Values Added |
---|---|---|
First Time |
Jetplugs revision Manager Tmc
Jetplugs |
|
CPE | cpe:2.3:a:jetplugs:revision_manager_tmc:*:*:*:*:*:wordpress:*:* | |
Summary |
|
|
References | () https://plugins.trac.wordpress.org/browser/revision-manager-tmc/trunk/src/Components/Notifications.php#L357 - Product | |
References | () https://plugins.trac.wordpress.org/changeset/3147298/ - Patch | |
References | () https://www.wordfence.com/threat-intel/vulnerabilities/id/2c8a6ff9-6aa8-4e0f-b058-759561a55508?source=cve - Third Party Advisory |
06 Sep 2024, 14:15
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2024-09-06 14:15
Updated : 2024-09-26 21:42
NVD link : CVE-2024-7622
Mitre link : CVE-2024-7622
CVE.ORG link : CVE-2024-7622
JSON object : View
Products Affected
jetplugs
- revision_manager_tmc
CWE
CWE-862
Missing Authorization