Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WP Mailster allows Stored XSS.This issue affects WP Mailster: from n/a through 1.8.16.0.
Fixes

Solution

Update the WordPress WP Mailster plugin to the latest available version (at least 1.8.17.0).


Workaround

No workaround given by the vendor.

History

Mon, 10 Feb 2025 18:45:00 +0000

Type Values Removed Values Added
First Time appeared Wpmailster
Wpmailster wp Mailster
CPEs cpe:2.3:a:wpmailster:wp_mailster:*:*:*:*:*:wordpress:*:*
Vendors & Products Wpmailster
Wpmailster wp Mailster

Thu, 28 Nov 2024 13:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 28 Nov 2024 11:15:00 +0000

Type Values Removed Values Added
Description Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WP Mailster allows Stored XSS.This issue affects WP Mailster: from n/a through 1.8.16.0.
Title WordPress WP Mailster plugin <= 1.8.16.0 - Cross Site Scripting (XSS) vulnerability
Weaknesses CWE-79
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L'}


cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2024-11-28T12:15:16.366Z

Reserved: 2024-11-22T13:51:57.971Z

Link: CVE-2024-53737

cve-icon Vulnrichment

Updated: 2024-11-28T12:09:16.008Z

cve-icon NVD

Status : Analyzed

Published: 2024-11-28T11:15:54.407

Modified: 2025-02-10T18:22:34.850

Link: CVE-2024-53737

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.