6.5
CVSSv3

CVE-2022-2370

Published: 01/08/2022 Updated: 07/11/2023
CVSS v3 Base Score: 6.5 | Impact Score: 3.6 | Exploitability Score: 2.8
VMScore: 0

Vulnerability Summary

The YaySMTP WordPress plugin prior to 2.2.1 does not have capability check before displaying the Mailer Credentials in JS code for the settings, allowing any authenticated users, such as subscriber to retrieve them

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

yaycommerce yaysmtp