What the vulnerability does
01Description
Missing Authorization vulnerability in Matt Miller Send Emails with Mandrill send-emails-with-mandrill allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Send Emails with Mandrill: from n/a through <= 1.4.1.
Explanation of Vulnerability in Simple Terms
02Summary
The Send Emails with Mandrill plugin fails to properly check user permissions before allowing access to certain functions. A logged-in user with low privileges can read email configuration details and potentially view sensitive data. The vulnerability affects versions up to 1.4.1. Update to a version newer than 1.4.1 to resolve this issue.
What an attacker can do
03Attacker Capabilities
Read email configuration and sensitive data without proper authorization.
Potential impact on your site
04Site Impact
Unauthorized users can access email settings and configuration details stored by the plugin.
Conditions required to exploit
05Prerequisites
Attacker must be logged in as a low-privilege user (e.g., subscriber or contributor).
Key dates
06Disclosure timeline
November 1, 2024
CVE published
April 28, 2026
Record updated