ZeroHour

CVE-2023-5958

PoC
CVSS 3.1
6.1 medium
EPSS
<1%p42
Published
()
Modified
Description

The POST SMTP Mailer WordPress plugin before 2.7.1 does not escape email message content before displaying it in the backend, allowing an unauthenticated attacker to perform XSS attacks against highly privileged users.

Vendors
wpexperts
Products
post smtp
Ecosystems
WordPress
Weakness
CWE-79
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

In the news

No ingested article mentions this CVE yet.