Qubely < 1.8.6 - Unauthenticated Arbitrary E-mail Sending
18Vexday Risk Score
Patch soon. It has a working public exploit.
ssvc Attendepss 1.7%
exploitation probability
1.7%top 25% of all CVEs
observed exploitation
nono source reports it
The Qubely WordPress plugin before 1.8.6 allows unauthenticated user to send arbitrary e-mails to arbitrary addresses via the qubely_send_form_data AJAX action.
Affected products
Unknown · Qubely