Super Store Finder <= 6.9.3 - Unauthenticated Email Creation/Sending

2023-09-18 00:00
Etharus

Strategic Overview

Status
Patched in 6.9.4
Affected PluginSuper Store Finder
Affected Version<= 6.9.3
CVSS5.8Medium
CVECVE-2023-5054
View all Super Store Finder vulnerabilities

Vulnerability Overview

The Super Store Finder plugin for WordPress is vulnerable to unauthenticated arbitrary email creation and relay in versions up to, and including, 6.9.3. This is due to insufficient restrictions on the sendMail.php file that allows direct access. This makes it possible for unauthenticated attackers to send emails utilizing the vulnerable site's server, with arbitrary content. Please note that this vulnerability has already been publicly disclosed with an exploit which is why we are publishing the details without a patch available, we are attempting to initiate contact with the developer.

Technical Analysis

REMEDIATION: Update to version 6.9.4, or a newer patched version --- IDENTIFIER: CWE-862 (Missing Authorization) The product does not perform an authorization check when an actor attempts to access a resource or perform an action.

External References

Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C