Showing 1 vulnerability on this page for wordpress_email_template_designer

Signals CISA KEV Ransomware Nuclei
codemiq vulnerability results
VulnerabilityTitle and contextCVSSEPSSPoCsSignalsSTIX action

WP HTML Mail <= 3.0.9 Missing Authorization on REST-API Route

The WP HTML Mail WordPress plugin is vulnerable to unauthorized access which allows unauthenticated attackers to retrieve and modify theme settings due to a missing capability check on the /themesettings REST-API endpoint found in the ~/includes/class-template-designer.php file, in versions up to and including 3.0.9. This makes it possible for attackers with no privileges to execute the endpoint and add malicious JavaScript to a vulnerable WordPress site.

CWE-79CWE-862Feb 4, 20221 related artifact
CVSS8.3v3.1EPSS70.5%PoCs0SignalsNot listed in CISA KEVNo known ransomware use1 Nuclei templateSTIX