Stored Cross-Site Scripting in SMTP Mail Plugin for WordPress
CVE-2023-3092

7.2HIGH

Key Information:

Vendor
WordPress
Status
Vendor
CVE Published:
12 July 2023

Summary

The SMTP Mail plugin for WordPress is susceptible to Stored Cross-Site Scripting due to inadequate input sanitization and output escaping in the 'Save Data SendMail' feature. This vulnerability allows unauthenticated attackers to inject malicious web scripts through manipulated email subjects, which could be executed when users access targeted pages. Users should update to the latest version of the plugin to safeguard against potential attacks.

Affected Version(s)

SMTP Mail * <= 1.2.16

References

CVSS V3.1

Score:
7.2
Severity:
HIGH
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Alex Thomas
.