CVE-2024-4787

June 19, 2024, 4:15 a.m.

Received
CVE has been recently published to the CVE List and has been received by the NVD.

Products

Cost Calculator Builder PRO for WordPress

  • up to 3.1.75

Source

security@wordfence.com

Tags

CVE-2024-4787 details

Published : June 19, 2024, 4:15 a.m.
Last Modified : June 19, 2024, 4:15 a.m.

Description

The Cost Calculator Builder PRO for WordPress is vulnerable to arbitrary email sending vulnerability in versions up to, and including, 3.1.75. This is due to insufficient limitations on the email recipient and the content in the 'send_pdf' and the 'send_pdf_front' functions which are reachable via AJAX. This makes it possible for unauthenticated attackers to send emails with any content to any recipient.

CVSS Score

1 2 3 4 5.8 6 7 8 9 10

Weakness

Weakness Name Description

CVSS Data

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

Scope

CHANGED

Confidentiality Impact

NONE

Integrity Impact

LOW

Availability Impact

NONE

Base Score

5.8

Exploitability Score

3.9

Impact Score

1.4

Base Severity

MEDIUM

This website uses the NVD API, but is not approved or certified by it.