WordPress AcyMailing SMTP Newsletter Plugin <= 8.6.2 is vulnerable to Cross Site Scripting (XSS)
CVE-2023-41867
7.1HIGH
What is CVE-2023-41867?
The AcyMailing plugin for WordPress has a reflected Cross-Site Scripting (XSS) vulnerability that affects versions 8.6.2 and earlier. This flaw allows attackers to inject malicious scripts through a crafted URL, enabling unauthorized access to user data and potentially leading to further exploitation of the site. Website administrators using AcyMailing should update their plugins immediately to mitigate this risk and protect user data from malicious attacks. Ensure your plugins are always up to date to maintain optimal security.
Affected Version(s)
AcyMailing <= 8.6.2