
Cloud Vulnerability DB
A community-led vulnerabilities database
The Send email only on Reply to My Comment WordPress plugin through version 1.0.6 contains a vulnerability related to missing CSRF protection and inadequate input sanitization. The vulnerability was discovered and publicly disclosed on July 9, 2024, affecting all versions of the plugin up to 1.0.6 (WPScan).
The vulnerability stems from two main security issues: lack of CSRF (Cross-Site Request Forgery) checks in certain areas of the plugin, and insufficient sanitization and escaping of input data. These security gaps could be exploited through a CSRF attack to inject stored XSS (Cross-Site Scripting) payloads when a logged-in administrator is targeted. The vulnerability has been assigned a CVSS v3.1 base score of 5.9 (Medium) with the vector string CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:L (CISA-ADP).
If successfully exploited, this vulnerability allows attackers to store XSS payloads in the system through CSRF attacks when targeting logged-in administrators. This could potentially lead to the execution of malicious scripts in the administrator's browser context, potentially compromising the security of the WordPress installation (WPScan).
The vulnerability requires an attacker to craft a CSRF attack targeting a logged-in administrator. A proof of concept exists demonstrating that an administrator needs to open a specially crafted file to trigger the vulnerability, after which the XSS payload can be observed in the comment management screen (WPScan).
Currently, there is no known fix available for this vulnerability. Users of the affected plugin should consider either disabling it until a patch is released or implementing additional security measures to protect against CSRF attacks (WPScan).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."