Post SMTP < 2.1.7 - Admin+ Blind SSRF
21Vexday Risk Score
No sign of exploitation. No public exploitation artifact known so far.
ssvc Trackcvss 7.2epss 1.1%
exploitation probability
1.1%top 38% of all CVEs
observed exploitation
nono source reports it
The Post SMTP Mailer/Email Log WordPress plugin before 2.1.7 does not have proper authorisation in some AJAX actions, which could allow high privilege users such as admin to perform blind SSRF on multisite installations for example.
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Affected products
Unknown · Post SMTP Mailer/Email Log