CVE-2023-5672

MEDIUM

WP Mail Log < 1.1.3 - Local File Inclusion via Email Attachment Path Parameter

Title source: llm
STIX 2.1

Description

The WP Mail Log WordPress plugin before 1.1.3 does not properly validate file path parameters when attaching files to emails, leading to local file inclusion, and allowing an attacker to leak the contents of arbitrary files.

References (1)

Core 1
Core References
Exploit, Third Party Advisory exploit vdb-entry technical-description
https://wpscan.com/vulnerability/7c1dff5b-bed3-49f8-96cc-1bc9abe78749

Scores

CVSS v3 6.5
EPSS 0.0071
EPSS Percentile 48.7%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

CISA SSVC

Vulnrichment
Exploitation poc
Automatable no
Technical Impact partial

Details

CWE
CWE-22
Status published
Products (1)
wpvibes/wp_mail_log < 1.1.3
Published Dec 26, 2023
Tracked Since Feb 18, 2026