CVE-2023-7202

MEDIUM

Fatal Error Notify < 1.5.3 - Authenticated Cross-Site Request Forgery via test_error AJAX Action

Title source: llm
STIX 2.1

Description

The Fatal Error Notify WordPress plugin before 1.5.3 does not have authorisation and CSRF checks in its test_error AJAX action, allowing any authenticated users, such as subscriber to call it and spam the admin email address with error messages. The issue is also exploitable via CSRF

References (2)

Core 2
Core References
Exploit, Third Party Advisory exploit vdb-entry technical-description
https://wpscan.com/vulnerability/d923ba5b-1c20-40ee-ac69-cd0bb65b375a/

Scores

CVSS v3 6.1
EPSS 0.0023
EPSS Percentile 13.5%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:N/I:L/A:L

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-352
Status published
Products (1)
verygoodplugins/fatal_error_notify < 1.5.3
Published Feb 27, 2024
Tracked Since Feb 18, 2026