Description
The POST SMTP WordPress plugin before 2.8.7 does not sanitise and escape the msg parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2023-58844 | The POST SMTP WordPress plugin before 2.8.7 does not sanitise and escape the msg parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin. |
References
History
Wed, 18 Jun 2025 16:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Status: PUBLISHED
Assigner: WPScan
Published:
Updated: 2025-06-18T15:36:31.330Z
Reserved: 2023-12-08T10:31:08.620Z
Link: CVE-2023-6621
Updated: 2024-08-02T08:35:14.834Z
Status : Modified
Published: 2024-01-03T09:15:11.440
Modified: 2025-06-18T16:15:24.997
Link: CVE-2023-6621
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD