CVE-2023-1430
MEDIUM 6.5EPSS 0.8%
The FluentCRM - Marketing Automation For WordPress plugin for WordPress is vulnerable to unauthorized modification of data in versions up to, and including, 2.7.40 due to the use of an MD5 hash without a salt to control subscriptions. This makes it possible for unauthenticated attackers to unsubscribe users from lists and manage subscriptions, granted they gain access to any targeted subscribers email address.
- CVSS v3.1
- 3.7 LOW
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N - CVSS v3.1
- 6.5 MEDIUM
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N - EPSS
- 0.80% chance of exploitation in the next 30 days, 54th percentile
- Published
- 2023-06-09
- Updated
- 2026-04-08
Proof-of-concept exploits (1)
- karlemilnikka/CVE-2023-14300★ · 2024-01-27