PoC Index

CVE-2022-2352

HIGH 7.2EPSS 1.1%

The Post SMTP Mailer/Email Log WordPress plugin before 2.1.7 does not have proper authorisation in some AJAX actions, which could allow high privilege users such as admin to perform blind SSRF on multisite installations for example.

CVSS v3.1
7.2 HIGHCVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
CVSS v3.1
7.2 HIGHCVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
EPSS
1.12% chance of exploitation in the next 30 days, 64th percentile
Published
2022-09-26
Updated
2025-05-21

Proof-of-concept exploits (1)

References

Related