← Back to CVE List

CVE-2023-7202

Published: 2024-02-27T09:15Z
Last Modified: 2024-11-21T08:45Z
Source: MITRE CVE List
License: MITRE-CVE-TOS
The Fatal Error Notify WordPress plugin before 1.5.3 does not have authorisation and CSRF checks in its test_error AJAX action, allowing any authenticated users, such as subscriber to call it and spam the admin email address with error messages. The issue is also exploitable via CSRF > MITRE Terms of Use apply – see LICENSE‑MITRE.txt