Stored Cross-Site Scripting Vulnerability in WP Mail Logging for WordPress
CVE-2023-3081

6.1MEDIUM

Key Information:

Vendor
Wordpress
Vendor
CVE Published:
12 July 2023

Summary

The WP Mail Logging plugin for WordPress is susceptible to a stored cross-site scripting vulnerability due to inadequate input sanitization and output escaping mechanisms. This flaw allows unauthenticated attackers to inject arbitrary web scripts into email contents. These scripts could execute on impacted pages, potentially compromising user security when accessed. A partial fix was introduced in version 1.11.1, yet systems using prior versions remain exposed to such attacks.

Affected Version(s)

WP Mail Logging * <= 1.11.1

References

CVSS V3.1

Score:
6.1
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Alex Thomas
.