CVE-2017-6955

Severity CVSS v4.0:
Pending analysis
Type:
CWE-20 Input Validation
Publication date:
17/03/2017
Last modified:
20/04/2025

Description

An issue was discovered in by-email/by-email.php in the Invite Anyone plugin before 1.3.15 for WordPress. A user is able to change the subject and the body of the invitation mail that should be immutable, which facilitates a social engineering attack.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:teleogistic:invite_anyone:*:*:*:*:*:wordpress:*:* 1.3.13 (including)