Vulnerability Details CVE-2023-1844
The Subscribe2 plugin for WordPress is vulnerable to unauthorized access to email functionality due to a missing capability check when sending test emails in versions up to, and including, 10.40. This makes it possible for author-level attackers to send emails with arbitrary content and attachments to site users.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.001
EPSS Ranking 25.8%
CVSS Severity
CVSS v3 Score 4.3
Products affected by CVE-2023-1844
-
cpe:2.3:a:subscribe2_project:subscribe2:1.1
-
cpe:2.3:a:subscribe2_project:subscribe2:1.7
-
cpe:2.3:a:subscribe2_project:subscribe2:10.0
-
cpe:2.3:a:subscribe2_project:subscribe2:10.1
-
cpe:2.3:a:subscribe2_project:subscribe2:10.10
-
cpe:2.3:a:subscribe2_project:subscribe2:10.11
-
cpe:2.3:a:subscribe2_project:subscribe2:10.12
-
cpe:2.3:a:subscribe2_project:subscribe2:10.13
-
cpe:2.3:a:subscribe2_project:subscribe2:10.14
-
cpe:2.3:a:subscribe2_project:subscribe2:10.15
-
cpe:2.3:a:subscribe2_project:subscribe2:10.16
-
cpe:2.3:a:subscribe2_project:subscribe2:10.17
-
cpe:2.3:a:subscribe2_project:subscribe2:10.17.2
-
cpe:2.3:a:subscribe2_project:subscribe2:10.18
-
cpe:2.3:a:subscribe2_project:subscribe2:10.18.1
-
cpe:2.3:a:subscribe2_project:subscribe2:10.18.2
-
cpe:2.3:a:subscribe2_project:subscribe2:10.18.3
-
cpe:2.3:a:subscribe2_project:subscribe2:10.18.4
-
cpe:2.3:a:subscribe2_project:subscribe2:10.18.5
-
cpe:2.3:a:subscribe2_project:subscribe2:10.19.0
-
cpe:2.3:a:subscribe2_project:subscribe2:10.2
-
cpe:2.3:a:subscribe2_project:subscribe2:10.20.0
-
cpe:2.3:a:subscribe2_project:subscribe2:10.20.2
-
cpe:2.3:a:subscribe2_project:subscribe2:10.20.3
-
cpe:2.3:a:subscribe2_project:subscribe2:10.20.4
-
cpe:2.3:a:subscribe2_project:subscribe2:10.20.5
-
cpe:2.3:a:subscribe2_project:subscribe2:10.20.6
-
cpe:2.3:a:subscribe2_project:subscribe2:10.20.7
-
cpe:2.3:a:subscribe2_project:subscribe2:10.20.8
-
cpe:2.3:a:subscribe2_project:subscribe2:10.20.9
-
cpe:2.3:a:subscribe2_project:subscribe2:10.21
-
cpe:2.3:a:subscribe2_project:subscribe2:10.22
-
cpe:2.3:a:subscribe2_project:subscribe2:10.22.1
-
cpe:2.3:a:subscribe2_project:subscribe2:10.26
-
cpe:2.3:a:subscribe2_project:subscribe2:10.26.1
-
cpe:2.3:a:subscribe2_project:subscribe2:10.27
-
cpe:2.3:a:subscribe2_project:subscribe2:10.28
-
cpe:2.3:a:subscribe2_project:subscribe2:10.3
-
cpe:2.3:a:subscribe2_project:subscribe2:10.30
-
cpe:2.3:a:subscribe2_project:subscribe2:10.31
-
cpe:2.3:a:subscribe2_project:subscribe2:10.32
-
cpe:2.3:a:subscribe2_project:subscribe2:10.33
-
cpe:2.3:a:subscribe2_project:subscribe2:10.34
-
cpe:2.3:a:subscribe2_project:subscribe2:10.35
-
cpe:2.3:a:subscribe2_project:subscribe2:10.36
-
cpe:2.3:a:subscribe2_project:subscribe2:10.37
-
cpe:2.3:a:subscribe2_project:subscribe2:10.38
-
cpe:2.3:a:subscribe2_project:subscribe2:10.39
-
cpe:2.3:a:subscribe2_project:subscribe2:10.4
-
cpe:2.3:a:subscribe2_project:subscribe2:10.40
-
cpe:2.3:a:subscribe2_project:subscribe2:10.5
-
cpe:2.3:a:subscribe2_project:subscribe2:10.6
-
cpe:2.3:a:subscribe2_project:subscribe2:10.8
-
cpe:2.3:a:subscribe2_project:subscribe2:10.9
-
cpe:2.3:a:subscribe2_project:subscribe2:2.1
-
cpe:2.3:a:subscribe2_project:subscribe2:2.10
-
cpe:2.3:a:subscribe2_project:subscribe2:2.11
-
cpe:2.3:a:subscribe2_project:subscribe2:2.12
-
cpe:2.3:a:subscribe2_project:subscribe2:2.13
-
cpe:2.3:a:subscribe2_project:subscribe2:2.14
-
cpe:2.3:a:subscribe2_project:subscribe2:2.15
-
cpe:2.3:a:subscribe2_project:subscribe2:2.16
-
cpe:2.3:a:subscribe2_project:subscribe2:2.17
-
cpe:2.3:a:subscribe2_project:subscribe2:2.18
-
cpe:2.3:a:subscribe2_project:subscribe2:2.19
-
cpe:2.3:a:subscribe2_project:subscribe2:2.2
-
cpe:2.3:a:subscribe2_project:subscribe2:2.20
-
cpe:2.3:a:subscribe2_project:subscribe2:2.21
-
cpe:2.3:a:subscribe2_project:subscribe2:2.22
-
cpe:2.3:a:subscribe2_project:subscribe2:2.5
-
cpe:2.3:a:subscribe2_project:subscribe2:2.6
-
cpe:2.3:a:subscribe2_project:subscribe2:2.7
-
cpe:2.3:a:subscribe2_project:subscribe2:2.8
-
cpe:2.3:a:subscribe2_project:subscribe2:2.9
-
cpe:2.3:a:subscribe2_project:subscribe2:3.0
-
cpe:2.3:a:subscribe2_project:subscribe2:3.1
-
cpe:2.3:a:subscribe2_project:subscribe2:3.2
-
cpe:2.3:a:subscribe2_project:subscribe2:3.3
-
cpe:2.3:a:subscribe2_project:subscribe2:3.4
-
cpe:2.3:a:subscribe2_project:subscribe2:3.5
-
cpe:2.3:a:subscribe2_project:subscribe2:3.6
-
cpe:2.3:a:subscribe2_project:subscribe2:3.7
-
cpe:2.3:a:subscribe2_project:subscribe2:3.8
-
cpe:2.3:a:subscribe2_project:subscribe2:4.0
-
cpe:2.3:a:subscribe2_project:subscribe2:4.1
-
cpe:2.3:a:subscribe2_project:subscribe2:4.10
-
cpe:2.3:a:subscribe2_project:subscribe2:4.11
-
cpe:2.3:a:subscribe2_project:subscribe2:4.12
-
cpe:2.3:a:subscribe2_project:subscribe2:4.13
-
cpe:2.3:a:subscribe2_project:subscribe2:4.14
-
cpe:2.3:a:subscribe2_project:subscribe2:4.15
-
cpe:2.3:a:subscribe2_project:subscribe2:4.16
-
cpe:2.3:a:subscribe2_project:subscribe2:4.17
-
cpe:2.3:a:subscribe2_project:subscribe2:4.18
-
cpe:2.3:a:subscribe2_project:subscribe2:4.2
-
cpe:2.3:a:subscribe2_project:subscribe2:4.3
-
cpe:2.3:a:subscribe2_project:subscribe2:4.4
-
cpe:2.3:a:subscribe2_project:subscribe2:4.5
-
cpe:2.3:a:subscribe2_project:subscribe2:4.6
-
cpe:2.3:a:subscribe2_project:subscribe2:4.7
-
cpe:2.3:a:subscribe2_project:subscribe2:4.8
-
cpe:2.3:a:subscribe2_project:subscribe2:4.9
-
cpe:2.3:a:subscribe2_project:subscribe2:5.0
-
cpe:2.3:a:subscribe2_project:subscribe2:5.0.1
-
cpe:2.3:a:subscribe2_project:subscribe2:5.1
-
cpe:2.3:a:subscribe2_project:subscribe2:5.2
-
cpe:2.3:a:subscribe2_project:subscribe2:5.3
-
cpe:2.3:a:subscribe2_project:subscribe2:5.4
-
cpe:2.3:a:subscribe2_project:subscribe2:5.5
-
cpe:2.3:a:subscribe2_project:subscribe2:5.6
-
cpe:2.3:a:subscribe2_project:subscribe2:5.7
-
cpe:2.3:a:subscribe2_project:subscribe2:5.8
-
cpe:2.3:a:subscribe2_project:subscribe2:5.9
-
cpe:2.3:a:subscribe2_project:subscribe2:6.0
-
cpe:2.3:a:subscribe2_project:subscribe2:6.1
-
cpe:2.3:a:subscribe2_project:subscribe2:6.2
-
cpe:2.3:a:subscribe2_project:subscribe2:6.3
-
cpe:2.3:a:subscribe2_project:subscribe2:6.4
-
cpe:2.3:a:subscribe2_project:subscribe2:6.5
-
cpe:2.3:a:subscribe2_project:subscribe2:7.0
-
cpe:2.3:a:subscribe2_project:subscribe2:7.0.1
-
cpe:2.3:a:subscribe2_project:subscribe2:7.1
-
cpe:2.3:a:subscribe2_project:subscribe2:7.2
-
cpe:2.3:a:subscribe2_project:subscribe2:8.0
-
cpe:2.3:a:subscribe2_project:subscribe2:8.1
-
cpe:2.3:a:subscribe2_project:subscribe2:8.2
-
cpe:2.3:a:subscribe2_project:subscribe2:8.3
-
cpe:2.3:a:subscribe2_project:subscribe2:8.4
-
cpe:2.3:a:subscribe2_project:subscribe2:8.5
-
cpe:2.3:a:subscribe2_project:subscribe2:8.6
-
cpe:2.3:a:subscribe2_project:subscribe2:8.7
-
cpe:2.3:a:subscribe2_project:subscribe2:8.8
-
cpe:2.3:a:subscribe2_project:subscribe2:8.9
-
cpe:2.3:a:subscribe2_project:subscribe2:8.9.1
-
cpe:2.3:a:subscribe2_project:subscribe2:9.0
-
cpe:2.3:a:subscribe2_project:subscribe2:9.1
-
cpe:2.3:a:subscribe2_project:subscribe2:9.2
-
cpe:2.3:a:subscribe2_project:subscribe2:9.3
-
cpe:2.3:a:subscribe2_project:subscribe2:9.4