ZeroHour

CVE-2023-0219

PoC
CVSS 3.1
5.4 medium
EPSS
<1%p42
Published
()
Modified
Description

The FluentSMTP WordPress plugin before 2.2.3 does not sanitize or escape email content, making it vulnerable to stored cross-site scripting attacks (XSS) when an administrator views the email logs. This exploit requires other plugins to enable users to send emails with unfiltered HTML.

Vendors
wpmanageninja
Products
fluentsmtp
Ecosystems
WordPress
Weakness
CWE-79
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N

In the news

No ingested article mentions this CVE yet.