The YaySMTP WordPress plugin prior to 2.2.1 does not have capability check in an AJAX action, allowing any logged in users, such as subscriber to view the Logs of the plugin
Vulnerable Product | Search on Vulmon | Subscribe to Product |
---|---|---|
yaycommerce yaysmtp |