What the vulnerability does
01Description
Unauthenticated Optin Campaign Cache Deletion vulnerability in MailOptin plugin <= 1.2.49.0 at WordPress.
CVSS base score
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L
What the vulnerability does
Unauthenticated Optin Campaign Cache Deletion vulnerability in MailOptin plugin <= 1.2.49.0 at WordPress.
Explanation of Vulnerability in Simple Terms
MailOptin version 1.2.49.0 and earlier lacks proper authorization checks, allowing unauthenticated attackers to modify site data. An attacker can send a network request to alter plugin settings or content without needing to log in. This affects the plugin's core functionality and could lead to unauthorized changes to email campaigns or subscriber data.
What an attacker can do
Modify plugin settings and data without logging in to the site.
Potential impact on your site
Attackers can alter MailOptin campaigns, subscriber lists, or settings without your knowledge or permission.
Conditions required to exploit
Network access to the site; no authentication or user interaction required.
Key dates
External resources
Related vulnerabilities