WP Mail Gateway Missing Authorization Vulnerability in WordPress
Vulnerability
A vulnerability exists in the WP Mail Gateway plugin for WordPress, specifically in versions through 1.8, due to a lack of proper capability checks on the 'wmg_save_provider_config' AJAX action. This flaw allows authenticated attackers with Subscriber-level access or higher to modify SMTP settings and redirect emails. Such actions could be exploited for privilege escalation by initiating a password reset process and using the reset link to gain access to an administrator's account.
Impact
Exploitation of this vulnerability could lead to unauthorized modification of SMTP configurations, allowing for email redirection and potential privilege escalation by accessing an administrator's account.
Remediation
Users can update to WP Mail Gateway version 1.8.1 or a newer patched version to address this vulnerability.
Vulnerability Rating
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.
