Impact
The twinklesmtp WordPress plugin contains a stored cross‑site scripting flaw in the sender settings that allows authenticated users with administrator privileges or higher to inject arbitrary JavaScript into the settings page. Because the input is not properly sanitized and the output is not escaped, a malicious actor can place scripts that will execute in the browser of any user who views that page. The vulnerability does not provide direct remote code execution; its impact is limited to what a user can do in the browser, such as hijacking sessions or defacing content.
Affected Systems
The flaw exists in all versions of twinklesmtp up to and including 1.03. The problem only manifests on multi‑site WordPress installations where the unfiltered_html capability has been disabled. Any site running an affected TwinkleSMTP version under these conditions is at risk.
Risk and Exploitability
The CVSS score of 4.4 indicates a moderate threat, while the EPSS score of less than 1% shows a very low probability of exploitation at the time of analysis. The vulnerability is not listed in the CISA KEV catalog. Exploitation requires an attacker to authenticate as an administrator and then submit malicious input through the sender settings interface; the malicious code is stored and later served to other users when they access the same page.
OpenCVE Enrichment