Cross-Site Scripting Flaw in Postie Plugin for WordPress
CVE-2019-20204
5.4MEDIUM
What is CVE-2019-20204?
The Postie plugin version 1.9.40 for WordPress is vulnerable to Cross-Site Scripting (XSS), which can be exploited through a specially crafted payload featuring an SVG element. Attackers can execute arbitrary JavaScript by injecting malicious code into fields accepted by the plugin, potentially compromising user data and website integrity.