Description
WordPress Plugin MailPress is prone to multiple vulnerabilities, including local file inclusion and security bypass vulnerabilities. Exploiting these issues could allow an attacker to obtain sensitive information that could aid in further attacks or to perform otherwise restricted actions and subsequently add or remove capabilities to WordPress roles. WordPress Plugin MailPress version 5.4.4 is vulnerable; prior versions may also be affected.
Remediation
Disable the plugin until a fix is available
References
Related Vulnerabilities
Liferay Portal Missing Authorization Vulnerability (CVE-2022-38512)
WordPress Plugin Mobile Domain Multiple Vulnerabilities (1.5.2)
TYPO3 Unrestricted Upload of File with Dangerous Type Vulnerability (CVE-2010-3663)
WordPress Plugin SpiderCatalog Unspecified Vulnerability (1.6.8)
ATutor Unrestricted Upload of File with Dangerous Type Vulnerability (CVE-2019-12170)