WordPress Qubely < 1.8.6 - Unauthenticated Email Sending
Qubely WordPress plugin < 1.8.6 contains an insecure deserialization caused by unauthenticated users being able to send arbitrary emails via the qubely_send_form_data AJAX action, letting attackers send spam or malicious emails, exploit requires no authentication.
qubelyPoC 已收录
CVSS—