Coming soon and Maintenance mode <= 3.6.6 - Missing Authorization to Arbitrary Email Send

2022-01-24 00:00
Krzysztof Zając

Strategic Overview

Status
Patched in 3.6.7
Affected Version<= 3.6.6
CVSS4.3Medium
CVECVE-2022-0164
View all Coming soon and Maintenance mode vulnerabilities

Vulnerability Overview

The Coming soon and Maintenance mode WordPress plugin before 3.6.8 does not have authorisation and CSRF checks in its coming_soon_send_mail AJAX action, allowing any authenticated users, with a role as low as subscriber to send arbitrary emails to all subscribed users.

Technical Analysis

REMEDIATION: Update to version 3.6.7, or a newer patched version --- IDENTIFIER: CWE-863 (Incorrect Authorization) The product performs an authorization check when an actor attempts to access a resource or perform an action, but it does not correctly perform the check.

External References

Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C