CVE-2023-1430
FluentCRM - Marketing Automation For WordPress <= 2.8.01 - Insufficient Use of Hash as Authorization Control
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
1Exploited in Wild
-Decision
Descriptions
The FluentCRM - Marketing Automation For WordPress plugin for WordPress is vulnerable to unauthorized modification of data in versions up to, and including, 2.7.40 due to the use of an MD5 hash without a salt to control subscriptions. This makes it possible for unauthenticated attackers to unsubscribe users from lists and manage subscriptions, granted they gain access to any targeted subscribers email address.
The FluentCRM - Marketing Automation For WordPress plugin for WordPress is vulnerable to unauthorized modification of data in versions up to, and including, 2.8.01 due to the use of an MD5 hash without a salt to control subscriptions. This makes it possible for unauthenticated attackers to unsubscribe users from lists and manage subscriptions, granted they gain access to any targeted subscribers email address.
CVSS Scores
SSVC
- Decision:Attend
Timeline
- 2023-03-16 CVE Reserved
- 2023-06-01 CVE Published
- 2024-01-27 First Exploit
- 2024-12-17 EPSS Updated
- 2024-12-28 CVE Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
CWE
- CWE-759: Use of a One-Way Hash without a Salt
CAPEC
References (3)
URL | Tag | Source |
---|---|---|
https://www.wordfence.com/threat-intel/vulnerabilities/id/de6da87e-8f7d-4120-8a1b-390ef7733d84?source=cve | Third Party Advisory |
URL | Date | SRC |
---|---|---|
https://github.com/karlemilnikka/CVE-2023-1430 | 2024-01-27 |
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Wpmanageninja Search vendor "Wpmanageninja" | Fluentcrm Search vendor "Wpmanageninja" for product "Fluentcrm" | <= 2.7.40 Search vendor "Wpmanageninja" for product "Fluentcrm" and version " <= 2.7.40" | wordpress |
Affected
|