[WordPress SMTP Plugin] CVE-2023-6875 + PoC
by who - Sunday January 14, 2024 at 05:40 PM
#11
Perfect thanks a lot my boy friend
Reply
#12
Thanks for sharing
Reply
#13
(Jan 14, 2024, 05:40 PM)who Wrote: This vulnerability makes it possible for unauthenticated threat actors to reset the API key used to authenticate to the mailer and view logs, including password reset emails on WordPress sites that use this plugin. We also received another submission shortly after for an Unauthenticated Stored Cross-Site Scripting vulnerability in POST SMTP Mailer plugin from another researcher. This vulnerability enables threat actors to inject malicious web scripts into pages.

Blog:
https://www.wordfence.com/blog/2024/01/t...ss-plugin/

PoC:

thank you my broo
Reply
#14
Thanks for sharing
Reply
#15
I am very curious on what exactly this would be.

This forum account is currently banned. Ban Length: Permanent (N/A Remaining)
Ban Reason: Leeching | http://c66go4clkqodr7tdjfu76jztjs7w7d3fajdeypxn73v4ju3dt7g5yyyd.onion/Forum-Ban-Appeals if you feel this is incorrect.
Reply


Possibly Related Threads…
Thread Author Replies Views Last Post
  POC CVE-2025-24071 caca28sapo1 16 1,067 2 hours ago
Last Post: ucy
  Google Dorks for finding SQL injection vulnerabilities and other security issues 1yush 68 3,438 2 hours ago
Last Post: 89UI
  New Zer0 Day Wordpress A3g00n 82 3,774 Yesterday, 01:14 PM
Last Post: wker
  {SECRET} DATABASE OF EXPLOITS lulagain 440 27,781 May 07, 2026, 09:44 PM
Last Post: caribou
  Dokan Pro Unauthenticated SQL Injection POC | CVSS 10 Loki 44 4,097 May 07, 2026, 04:45 PM
Last Post: Insulina

Forum Jump:


 Users browsing this forum: 1 Guest(s)