Access violation vulnerability in Emails Catch All 3.5.3

The Emails Catch All plugin for WordPress has a security issue that could allow unauthorized users to gain access to sensitive information. This is because the plugin does not properly restrict access to email logs, which means that attackers with certain levels of access could trigger a password reset email and view it in the logs. This could ultimately lead to them resetting a user’s password and accessing their account.

Detected in:

Emails Catch All fixed vulnerable versions: >= * <= 3.5.3

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.