CVE-2023-5644

HIGH

WP Mail Log < 1.1.3 - Incorrect Authorization via REST API Endpoints

Title source: llm
STIX 2.1

Description

The WP Mail Log WordPress plugin before 1.1.3 does not correctly authorize its REST API endpoints, allowing users with the Contributor role to view and delete data that should only be accessible to Admin users.

References (1)

Core 1
Core References
Exploit, Third Party Advisory exploit vdb-entry technical-description
https://wpscan.com/vulnerability/08f1d623-0453-4103-a9aa-2d0ddb6eb69e

Scores

CVSS v3 7.6
EPSS 0.0050
EPSS Percentile 38.8%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:L

CISA SSVC

Vulnrichment
Exploitation poc
Automatable no
Technical Impact total

Details

CWE
CWE-863
Status published
Products (1)
wpvibes/wp_mail_log < 1.1.3
Published Dec 26, 2023
Tracked Since Feb 18, 2026