Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

CVE-2022-0345— Better Notifications for WP < 1.8.7 - Email Address Disclosure

EPSS 0.09% · P26
Get alerts for future matching vulnerabilitiesLog in to subscribe

I. Basic Information for CVE-2022-0345

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
Better Notifications for WP < 1.8.7 - Email Address Disclosure
Source: NVD (National Vulnerability Database)
Vulnerability Description
The Customize WordPress Emails and Alerts WordPress plugin before 1.8.7 does not have authorisation and CSRF check in its bnfw_search_users AJAX action, allowing any authenticated users to call it and query for user e-mail prefixes (finding the first letter, then the second one, then the third one etc.).
Source: NVD (National Vulnerability Database)
CVSS Information
N/A
Source: NVD (National Vulnerability Database)
Vulnerability Type
N/A
Source: NVD (National Vulnerability Database)
Vulnerability Title
WordPress 信息泄露漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
WordPress是WordPress(Wordpress)基金会的一套使用PHP语言开发的博客平台。该平台支持在PHP和MySQL的服务器上架设个人博客网站。 WordPress plugin Emails and Alerts 存在信息泄露漏洞,该漏洞源于1.8.7之前的自定义WordPress电子邮件和提醒插件没有授权和CSRF检查其bnfw搜索用户的AJAX动作,允许任何通过身份验证的用户调用它并查询用户的电子邮件前缀(找到第一个字母,然后第二个,然后第三个,等等)。
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Affected Products

VendorProductAffected VersionsCPESubscribe
UnknownCustomize WordPress Emails and Alerts 0 ~ 1.8.7 -

II. Public POCs for CVE-2022-0345

#POC DescriptionSource LinkShenlong Link
AI-Generated POCPremium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2022-0345

登录查看更多情报信息。

Same Patch Batch · Unknown · 2022-02-28 · 37 CVEs total

CVE-2022-0189WP RSS Aggregator < 4.20 - Reflected Cross-Site Scripting (XSS)
CVE-2021-25011WP Google Map < 1.8.1 - Subscriber+ Arbitrary Post Deletion and Plugin's Settings Update
CVE-2021-25034WP User < 7.0 - Reflected Cross-Site Scripting
CVE-2021-25042WP Visitor Statistics (Real Time Traffic) < 5.5 - Arbitrary IP Address Exclusion to Stored
CVE-2021-25081WP Google Map < 1.8.4 - Arbitrary Post Deletion and Plugin's Settings Update via CSRF
CVE-2021-25112WHMCS Bridge < 6.4b - Reflected Cross-Site Scripting (XSS)
CVE-2021-25118Yoast SEO 16.7-17.2 - Unauthenticated Full Path Disclosure
CVE-2021-4222WP Paginate < 2.1.4 - Admin+ Stored Cross-Site Scripting
CVE-2022-0150WP Accessibility Helper (WAH) < 0.6.0.7 - Reflected Cross-Site Scripting (XSS)
CVE-2021-25010Post Snippets < 3.1.4 - CSRF to Stored Cross-Site Scripting
CVE-2022-0328Simple Membership < 4.0.9 - Arbitrary Member Deletion via CSRF
CVE-2022-0360WP Ultimate CSV Importer < 6.4.3 - Admin+ Stored Cross-Site Scripting
CVE-2022-0377LearnPress < 4.1.5 - Arbitrary Image Renaming
CVE-2022-0383WP Review Slider < 11.0 - Admin+ SQL Injection
CVE-2022-0385Crazy Bone <= 0.6.0 - Unauthenticated Stored XSS
CVE-2022-0411Asgaros Forum < 2.0.0 - Subscriber+ Blind SQL Injection
CVE-2022-23911AP Custom Testimonial < 1.4.8 - Admin+ SQL Injection
CVE-2022-23912AP Custom Testimonial < 1.4.8 - Reflected Cross-Site Scripting
CVE-2021-24898EditableTable <= 0.1.4 - Admin+ Stored Cross-Site Scripting
CVE-2021-24688Orange Form <= 1.0.1 - Unauthenticated Arbitrary Post Deletion

Showing top 20 of 37 CVEs. View all on vendor page &rarr; →

IV. Related Vulnerabilities

V. Comments for CVE-2022-0345

No comments yet


Leave a comment