CVE-2023-5958Cross-site Scripting in Post Smtp

Severity
6.1MEDIUMNVD
EPSS
0.8%
top 26.30%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedNov 27

Description

The POST SMTP Mailer WordPress plugin before 2.7.1 does not escape email message content before displaying it in the backend, allowing an unauthenticated attacker to perform XSS attacks against highly privileged users.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:NExploitability: 2.8 | Impact: 2.7

Affected Packages1 packages

NVDwpexperts/post_smtp< 2.7.1

🔴Vulnerability Details

2
CVEList
POST SMTP Mailer < 2.7.1 - Unauthenticated Cross-site Scripting2023-11-27
GHSA
GHSA-2r79-jc6j-hh65: The POST SMTP Mailer WordPress plugin before 22023-11-27
CVE-2023-5958 — Cross-site Scripting in Post Smtp | cvebase