NA

CVE-2023-7202

Published: 27/02/2024 Updated: 27/02/2024

Vulnerability Summary

The Fatal Error Notify WordPress plugin prior to 1.5.3 does not have authorisation and CSRF checks in its test_error AJAX action, allowing any authenticated users, such as subscriber to call it and spam the admin email address with error messages. The issue is also exploitable via CSRF