Impact
The AcyMailing SMTP Newsletter plugin for WordPress contains a cross‑site scripting flaw that allows malicious script code to be injected into subscriber data. When the data is later displayed, the injected script executes within the plugin’s page, potentially allowing an attacker to steal session cookies, hijack user accounts, or deface the site. This flaw is classified as CWE‑79, dealing with improper neutralization of input. The impact is a loss of confidentiality and integrity for visitor sessions and a possible compromise of the site’s appearance.
Affected Systems
Affected systems include installations of the AcyMailing SMTP Newsletter plugin up to and including version 10.11.1. Versions 11.0.0 and later incorporate the fix. The plugin is distributed by the AcyMailing Newsletter Team.
Risk and Exploitability
The CVSS score of 6.5 indicates a moderate severity. The EPSS score is not available and the vulnerability is not listed in the CISA KEV catalog, suggesting no documented public exploits. The likely attack vector involves submitting malicious subscriber data through public subscription forms or an authorized administrator interface, after which an unsuspecting visitor must view the affected page for the script to execute. While no exploit has been observed, the potential to execute arbitrary code in the user’s browser warrants prompt remediation.
OpenCVE Enrichment