all InfoSec news
Type Juggling Leads to Two Vulnerabilities in POST SMTP Mailer WordPress Plugin
Malware Analysis, News and Indicators - Latest topics malware.news
On December 14th, 2023, during our Bug Bounty Program Holiday Bug Extravaganza, we received a submission for an Authorization Bypass vulnerability in POST SMTP Mailer, a WordPress plugin with over 300,000+ active installations. This vulnerability makes it possible for unauthenticated threat actors to reset the API key used to authenticate to the mailer and view logs, including password reset emails on WordPress sites that use this plugin. We also received another submission shortly after for an Unauthenticated Stored Cross-Site …
api authorization bounty bug bug bounty bug bounty program bypass bypass vulnerability december holiday key plugin program reset smtp submission threat threat actors unauthenticated vulnerabilities vulnerability wordpress wordpress plugin