Mail Mint WordPress Plugin Cross-Site Request Forgery Vulnerability
Vulnerability
A Cross-Site Request Forgery (CSRF) vulnerability has been identified in the Mail Mint plugin for WordPress, affecting all versions through 1.19.2. The issue arises from inadequate nonce validation in the 'create_or_update_note' function, allowing unauthenticated attackers to manipulate contact notes by deceiving site administrators into clicking a link. This vulnerability also lacks proper data sanitization and escaping, potentially leading to stored Cross-Site Scripting (XSS) attacks.
Impact
Exploitation of this vulnerability could result in unauthorized modifications to contact notes, with the possibility of introducing malicious scripts that are stored and executed in the context of the user.
Reproduction
To reproduce this vulnerability, an attacker must craft a request to the 'create_or_update_note' endpoint without a valid nonce. This can be done by tricking an administrator into clicking a link that sends the request, such as through a phishing email or a compromised website.
Remediation
Users are advised to update the Mail Mint plugin to version 1.19.3 or later, where this vulnerability has been patched.
Vulnerability Rating
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.
