Reflected Cross-Site Scripting Vulnerability in Woo Custom Emails for WordPress
CVE-2023-4315
6.1MEDIUM
What is CVE-2023-4315?
The Woo Custom Emails plugin for WordPress is exposed to a Reflected Cross-Site Scripting vulnerability due to insufficient sanitization in the wcemails_edit parameter. This flaw allows unauthenticated attackers to inject malicious scripts into web pages, which execute when unsuspecting users are lured into clicking on manipulated links. Update to the latest version to mitigate this risk.
Affected Version(s)
Woo Custom Emails * <= 2.2