Description
The YaySMTP WordPress plugin before 2.2.1 does not have proper authorisation when saving its settings, allowing users with a role as low as subscriber to change them, and use that to conduct Stored Cross-Site Scripting attack due to the lack of escaping in them as well.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2022-34638 | The YaySMTP WordPress plugin before 2.2.1 does not have proper authorisation when saving its settings, allowing users with a role as low as subscriber to change them, and use that to conduct Stored Cross-Site Scripting attack due to the lack of escaping in them as well. |
References
History
No history.
Status: PUBLISHED
Assigner: WPScan
Published:
Updated: 2024-08-03T00:32:09.561Z
Reserved: 2022-07-11T00:00:00.000Z
Link: CVE-2022-2371
No data.
Status : Modified
Published: 2022-08-08T14:15:08.960
Modified: 2024-11-21T07:00:51.480
Link: CVE-2022-2371
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD