[WordPress SMTP Plugin] CVE-2023-6875 + PoC
by who - Sunday January 14, 2024 at 05:40 PM
#1
This vulnerability makes it possible for unauthenticated threat actors to reset the API key used to authenticate to the mailer and view logs, including password reset emails on WordPress sites that use this plugin. We also received another submission shortly after for an Unauthenticated Stored Cross-Site Scripting vulnerability in POST SMTP Mailer plugin from another researcher. This vulnerability enables threat actors to inject malicious web scripts into pages.

Blog:
https://www.wordfence.com/blog/2024/01/t...ss-plugin/

PoC:
Hidden Content
You must register or login to view this content.
⭐ ⭐ ⭐ ⭐ ⭐ ⭐ ⭐ ⭐ ⭐ ⭐ ⭐ ⭐ ⭐ ⭐ ⭐ ⭐
⭐ ⭐ ⭐ ⭐ ⭐Sharing is Caring⭐ ⭐ ⭐ ⭐ ⭐
⭐ ⭐ ⭐ ⭐ ⭐ ⭐ ⭐ ⭐ ⭐ ⭐ ⭐ ⭐ ⭐ ⭐ ⭐ ⭐
Reply
#2
I posted a video about this
Reply
#3
(Jan 14, 2024, 06:58 PM)zinzeur Wrote: I posted a video about this

put it here
⭐ ⭐ ⭐ ⭐ ⭐ ⭐ ⭐ ⭐ ⭐ ⭐ ⭐ ⭐ ⭐ ⭐ ⭐ ⭐
⭐ ⭐ ⭐ ⭐ ⭐Sharing is Caring⭐ ⭐ ⭐ ⭐ ⭐
⭐ ⭐ ⭐ ⭐ ⭐ ⭐ ⭐ ⭐ ⭐ ⭐ ⭐ ⭐ ⭐ ⭐ ⭐ ⭐
Reply
#4
Nice sharing. Im gonna check it out!

This forum account is currently banned. Ban Length: Permanent (N/A Remaining)
Ban Reason: Leeching | http://c66go4clkqodr7tdjfu76jztjs7w7d3fajdeypxn73v4ju3dt7g5yyyd.onion/Forum-Ban-Appeals if you feel this is incorrect.
Reply
#5
Thanks for sharing
Reply
#6
(Jan 14, 2024, 06:58 PM)zinzeur Wrote: I posted a video about this

i have a question... is there any way for us to discover wp websites that have that smtp mailer plugin installed.
Reply
#7
Where I can check video?
Reply
#8
nice share, who ever used it there?
Reply
#9
(Jan 14, 2024, 05:40 PM)who Wrote: This vulnerability makes it possible for unauthenticated threat actors to reset the API key used to authenticate to the mailer and view logs, including password reset emails on WordPress sites that use this plugin. We also received another submission shortly after for an Unauthenticated Stored Cross-Site Scripting vulnerability in POST SMTP Mailer plugin from another researcher. This vulnerability enables threat actors to inject malicious web scripts into pages.

Blog:
https://www.wordfence.com/blog/2024/01/t...ss-plugin/

PoC:

thks very much i will use a lot
Reply
#10
mega share or leav the marjet

This forum account is currently banned. Ban Length: Permanent (N/A Remaining)
Ban Reason: Fabricated evidence | Retarded Monkey
Reply


Possibly Related Threads…
Thread Author Replies Views Last Post
  {SECRET} DATABASE OF EXPLOITS lulagain 437 26,627 10 minutes ago
Last Post: XRDTX
  [POC] Google OAuth "MultiLogin" endpoint 0-day Farfallaiero 108 13,758 8 hours ago
Last Post: nobcoderfck
  Ban Any Discord Exploit phineasfisherman 7 463 Yesterday, 10:16 AM
Last Post: sniperx86
  Dokan Pro Unauthenticated SQL Injection POC | CVSS 10 Loki 42 3,775 Yesterday, 08:39 AM
Last Post: d39ug
  New Zer0 Day Wordpress A3g00n 81 3,403 May 05, 2026, 03:06 AM
Last Post: DirtyEra

Forum Jump:


 Users browsing this forum: 1 Guest(s)