CVE-2024-6591 Information
Description
The Ultimate WordPress Auction Plugin plugin for WordPress is vulnerable to unauthorized email creation and sending due to a missing capability check on the ‘send_auction_email_callback’ and ‘resend_auction_email_callback’ functions in all versions up to and including 4.2.6. This makes it possible for unauthenticated attackers to craft emails that include links and send to any email address.
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:L/A:N
Reference
https://www.wordfence.com/threat-intel/vulnerabilities/id/534a5d1d-cc34-4d84-b3a3-bf2282718656?source=cve https://plugins.trac.wordpress.org/browser/ultimate-auction/trunk/ultimate-auction.php#L93 https://plugins.trac.wordpress.org/browser/ultimate-auction/trunk/ultimate-auction.php#L119
Attack Complexity
LOW
Privileges Required
NONE
User Interaction Required
NONE
Scope
NONE
Confidentiality Impact
CHANGED
Integrity Impact
NONE
Availability Impact
LOW
Base Score
NONE
Base Severity
5.8
Share on: