Skip to main content

CVE-2022-0218

8.3
HIGHCVSS v3.1 Base Score
50.80%
MEDIUM RiskEPSS (98th percentile)

The WP HTML Mail WordPress plugin is vulnerable to unauthorized access which allows unauthenticated attackers to retrieve and modify theme settings due to a missing capability check on the /themesettings REST-API endpoint found in the ~/includes/class-template-designer.php file, in versions up to and including 3.0.9. This makes it possible for attackers with no privileges to execute the endpoint and add malicious JavaScript to a vulnerable WordPress site.

Published: 2/4/2022
Modified: 11/21/2024
Back to CVE Lookup

Vulnerability Summary

CVSS v3 Score

8.3HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:L

EPSS Score (Exploitation Probability)

50.80%MEDIUM Exploitation Risk
98th percentile

This vulnerability has a 50.80% probability of being exploited in the next 30 days, ranking higher than 98% of all scored CVEs.

Related Vulnerabilities