CVE-2022-0199

CVE-2022-0199: Coming soon and Maintenance mode < 3.6.8 - Arbitrary Email Sending to Subscribed Users via CSRF

Vendor Unknown
Product Coming soon and Maintenance mode
Weakness CWE-352 · CSRF
Published February 21, 2022
Last update August 2, 2024

CVSS base score

What the vulnerability does

01Description

The Coming soon and Maintenance mode WordPress plugin before 3.6.8 does not have CSRF check in its coming_soon_send_mail AJAX action, allowing attackers to make logged in admin to send arbitrary emails to all subscribed users via a CSRF attack

Key dates

02Disclosure timeline

February 21, 2022 CVE published
August 2, 2024 Record updated

Related vulnerabilities

04Related CVE