CVE-2019-20203

MEDIUM

Postie < 1.9.40 - Authentication Bypass by Spoofing

Title source: rule
STIX 2.1

Description

The Authorized Addresses feature in the Postie plugin 1.9.40 for WordPress allows remote attackers to publish posts by spoofing the From information of an email message.

References (4)

Core 4
Core References
Product x_refsource_misc
https://postieplugin.com/
Release Notes, Vendor Advisory x_refsource_misc
https://wordpress.org/plugins/postie/#developers
Third Party Advisory x_refsource_misc
https://wpvulndb.com/vulnerabilities/10002

Scores

CVSS v3 5.3
EPSS 0.0067
EPSS Percentile 71.3%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N

Details

CWE
CWE-290
Status published
Products (1)
postieplugin/postie < 1.9.40
Published Jan 02, 2020
Tracked Since Feb 18, 2026