peter bassill · operator
$ cve CVE-2023-6875 JSON

CVE-2023-6875

9.8
CRITICAL · CVSS 3.1 · EPSS 90.3% (pctl 100)

Patch early

EPSS 90.3% — above the 10% action threshold.

Description

The POST SMTP Mailer – Email log, Delivery Failure Notifications and Best Mail SMTP for WordPress plugin for WordPress is vulnerable to unauthorized access of data and modification of data due to a type juggling issue on the connect-app REST endpoint in all versions up to, and including, 2.8.7. This makes it possible for unauthenticated attackers to reset the API key used to authenticate to the mailer and view logs, including password reset emails, allowing site takeover. CVE-2023-52233 appears to be a duplicate of this issue.

Scoring

CVSS9.8 (CRITICAL, v3.1)
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS90.34% — more likely to be exploited than 100% of all CVEs
WeaknessCWE-639
On CISA KEVno
Public exploitnone known
Published2024-01-11
Last modified2026-06-17

Affected (1)

VendorProduct
wpexpertspost smtp

References

→ the Explorer  ·  watch your stack  ·  NVD