Store Locator Plus < 4.2.27 - Email Injection

2015-01-17 00:00
Kacper Szurek

Strategic Overview

Status
Patched in 4.2.27
Affected Version< 4.2.27
CVSS5.3Medium
CVEN/A
View all Store Locator Plus® for WordPress vulnerabilities

Vulnerability Overview

The Store Locator Plus plugin for WordPress is vulnerable to Email Injection in versions before 4.2.27. This is due to nonce leakage. This makes it possible for attackers to send spam emails from a fake address.

Technical Analysis

REMEDIATION: Update to version 4.2.27, or a newer patched version --- IDENTIFIER: CWE-284 (Improper Access Control) The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor.

External References

Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C