CVE-2022-0345 is a medium-severity vulnerability affecting the Customize WordPress Emails and Alerts plugin prior to version 1.8.7. It allows any authenticated user to enumerate user email prefixes due to missing authorization and CSRF checks in the bnfw_search_users AJAX action. The vulnerability has a CVSS score of 4.3 (Medium) and could lead to information disclosure (CWE-352, CWE-862). There is no evidence of active exploitation, exploit code availability, or significant community discussion surrounding this CVE.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 1.8.7CPE matchmatch criteria | cpe:2.3:a:madewithfuel:customize_wordpress_emails_and_alerts:*:*:*:*:*:wordpress:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.