Vulnerabilities > CVE-2023-6496 - Missing Authorization vulnerability in Freeamigos Manage Notification E-Mails

047910
CVSS 5.3 - MEDIUM
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
LOW
Integrity impact
NONE
Availability impact
NONE
network
low complexity
freeamigos
CWE-862

Summary

The Manage Notification E-mails plugin for WordPress is vulnerable to Missing Authorization in all versions up to, and including, 1.8.5 via the card_famne_export_settings function. This makes it possible for unauthenticated attackers to obtain plugin settings.

Common Weakness Enumeration (CWE)