Entreprise d'experts en Sécurité Informatique : Audits et conseils en cybersécurité
Entreprise française de cybersécurité depuis 2004
☎ 03 60 47 09 81 - info@securiteinfo.com


CVE-2019-20203

Description

The Authorized Addresses feature in the Postie plugin 1.9.40 for WordPress allows remote attackers to publish posts by spoofing the From information of an email message.

POC

Reference

- https://github.com/V1n1v131r4/Exploiting-Postie-WordPress-Plugin-/blob/master/README.md

- https://wpvulndb.com/vulnerabilities/10002

Github

- https://github.com/20142995/nuclei-templates

- https://github.com/V1n1v131r4/Exploiting-Postie-WordPress-Plugin-

- https://github.com/V1n1v131r4/My-CVEs