Store Locator Plus < 4.2.27 - Email Injection
2015-01-17 00:00
Kacper SzurekStrategic Overview
StatusPatched in 4.2.27
Affected PluginStore Locator Plus® for WordPress
Affected Version
< 4.2.27CVSS5.3Medium
CVE
N/AVulnerability Overview
The Store Locator Plus plugin for WordPress is vulnerable to Email Injection in versions before 4.2.27. This is due to nonce leakage. This makes it possible for attackers to send spam emails from a fake address.
Technical Analysis
REMEDIATION: Update to version 4.2.27, or a newer patched version --- IDENTIFIER: CWE-284 (Improper Access Control) The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor.
External References
Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C