AUGUST 4, 2026
Live Feed
Back to database
Case File

CVE-2023-3179

HIGH · CVSS 8.8 EPSS 0.39%

Source: NVD + CISA KEV + EPSS (historical backfill) · Published 2023-07-17 · Last synced 2026-08-04

CyberRota Analysis

This is a high severity vulnerability with a CVSS score of 8.8. It affects WordPress.

CVE
CVE-2023-3179
Severity
HIGH
CVSS
8.8
EPSS
0.39%
WordPress

Original NVD Description

The POST SMTP Mailer WordPress plugin before 2.5.7 does not have proper CSRF checks in some AJAX actions, which could allow attackers to make logged in users with the manage_postman_smtp capability resend an email to an arbitrary address (for example a password reset email could be resent to an attacker controlled email, and allow them to take over an account).

Related CVEs

Other vulnerabilities affecting the same vendor(s)