The Fatal Error Notify WordPress plugin before 1.5.3 does not have authorisation and CSRF checks in its test_error AJAX action, allowing any authenticated users, such as subscriber to call it and spam the admin email address with error messages. The issue is also exploitable via CSRF
CVSS
No CVSS.
References
Link | Resource |
---|---|
https://research.cleantalk.org/cve-2023-7202-fatal-error-notify-error-email-sending-csrf/ | Exploit Third Party Advisory |
https://research.cleantalk.org/cve-2023-7202-fatal-error-notify-error-email-sending-csrf/ | Exploit Third Party Advisory |
https://wpscan.com/vulnerability/d923ba5b-1c20-40ee-ac69-cd0bb65b375a/ | Exploit Third Party Advisory |
https://wpscan.com/vulnerability/d923ba5b-1c20-40ee-ac69-cd0bb65b375a/ | Exploit Third Party Advisory |
Configurations
History
01 May 2025, 14:31
Type | Values Removed | Values Added |
---|---|---|
First Time |
Verygoodplugins
Verygoodplugins fatal Error Notify |
|
CPE | cpe:2.3:a:verygoodplugins:fatal_error_notify:*:*:*:*:*:wordpress:*:* | |
References | () https://research.cleantalk.org/cve-2023-7202-fatal-error-notify-error-email-sending-csrf/ - Exploit, Third Party Advisory | |
References | () https://wpscan.com/vulnerability/d923ba5b-1c20-40ee-ac69-cd0bb65b375a/ - Exploit, Third Party Advisory |
27 Feb 2024, 09:15
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2024-02-27 09:15
Updated : 2025-05-01 14:31
NVD link : CVE-2023-7202
Mitre link : CVE-2023-7202
JSON object : View
Products Affected
verygoodplugins
- fatal_error_notify
CWE
No CWE.