CyberRota Analysis
AI-GeneratedThe MailerPress plugin for WordPress is vulnerable due to a missing capability check on the `mailerpress/v1/contact` endpoint, allowing unauthenticated attackers to update contact details. This could lead to unauthorized modifications of user data, potentially compromising the integrity of email marketing campaigns. WordPress site administrators using this plugin should prioritize applying updates to mitigate this risk.
Original NVD Description
The MailerPress – Newsletter, email marketing & AI automation plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on the `mailerpress/v1/contact` endpoint in all versions up to, and including, 1.5.0. This makes it possible for unauthenticated attackers to update contact details.