Description
The FluentSMTP WordPress plugin before 2.2.3 does not sanitize or escape email content, making it vulnerable to stored cross-site scripting attacks (XSS) when an administrator views the email logs. This exploit requires other plugins to enable users to send emails with unfiltered HTML.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2023-12305 | The FluentSMTP WordPress plugin before 2.2.3 does not sanitize or escape email content, making it vulnerable to stored cross-site scripting attacks (XSS) when an administrator views the email logs. This exploit requires other plugins to enable users to send emails with unfiltered HTML. |
References
History
Tue, 04 Mar 2025 03:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Status: PUBLISHED
Assigner: WPScan
Published:
Updated: 2025-02-27T15:46:50.142Z
Reserved: 2023-01-11T12:20:09.137Z
Link: CVE-2023-0219
Updated: 2024-08-02T05:02:44.093Z
Status : Modified
Published: 2023-03-13T17:15:12.400
Modified: 2024-11-21T07:36:46.187
Link: CVE-2023-0219
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD