CyberRota Analysis
This is a medium severity vulnerability with a CVSS score of 5.8. It affects WordPress. Exploitation may require the attacker to be authenticated.
CVE
CVE-2024-6591
Severity
MEDIUM
CVSS
5.8
EPSS
0.40%
WordPress
Original NVD Description
The Ultimate WordPress Auction Plugin plugin for WordPress is vulnerable to unauthorized email creation and sending due to a missing capability check on the 'send_auction_email_callback' and 'resend_auction_email_callback' functions in all versions up to, and including, 4.2.7. This makes it possible for unauthenticated attackers to craft emails that include links and send to any email address.