PoC Index

CVE-2023-5672

MEDIUM 6.5EPSS 0.7%

The WP Mail Log WordPress plugin before 1.1.3 does not properly validate file path parameters when attaching files to emails, leading to local file inclusion, and allowing an attacker to leak the contents of arbitrary files.

CVSS v3.1
6.5 MEDIUMCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
EPSS
0.71% chance of exploitation in the next 30 days, 51th percentile
Published
2023-12-26
Updated
2024-11-21

Proof-of-concept exploits (1)

References

Related