Stored Cross-Site Scripting in SMTP Mail Plugin for WordPress
CVE-2023-3092
7.2HIGH
What is CVE-2023-3092?
The SMTP Mail plugin for WordPress is susceptible to Stored Cross-Site Scripting due to inadequate input sanitization and output escaping in the 'Save Data SendMail' feature. This vulnerability allows unauthenticated attackers to inject malicious web scripts through manipulated email subjects, which could be executed when users access targeted pages. Users should update to the latest version of the plugin to safeguard against potential attacks.
Affected Version(s)
SMTP Mail * <= 1.2.16