CVE-2019-20203

MEDIUM

Postie < 1.9.40 - Authentication Bypass via Email From Address Spoofing

Title source: llm
STIX 2.1

Description

The Authorized Addresses feature in the Postie plugin 1.9.40 for WordPress allows remote attackers to publish posts by spoofing the From information of an email message.

References (4)

Core 4
Core References
Product x_refsource_misc
https://postieplugin.com/
Release Notes, Vendor Advisory x_refsource_misc
https://wordpress.org/plugins/postie/#developers
Third Party Advisory x_refsource_misc
https://wpvulndb.com/vulnerabilities/10002

Scores

CVSS v3 5.3
EPSS 0.0210
EPSS Percentile 79.3%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N

Details

CWE
CWE-290
Status published
Products (1)
postieplugin/postie < 1.9.40
Published Jan 02, 2020
Tracked Since Feb 18, 2026