Sender Newsletter, SMS and Email Marketing Automation for WooCommerce vulnerable to Cross-site Scripting
CVE-2024-43126
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 12 August 2024
What is CVE-2024-43126?
The vulnerability arises from improper neutralization of user input during the web page generation process, facilitating reflected Cross-site Scripting (XSS) attacks. Attackers can exploit this flaw to inject malicious scripts into web pages rendered by users, potentially leading to session hijacking, data theft, or other unauthorized actions. The affected product, Sender β Newsletter, SMS and Email Marketing Automation for WooCommerce, has multiple versions influenced by this issue, including releases from n/a up to 2.6.14, highlighting the urgency for users to secure their installations.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
Sender β Newsletter, SMS and Email Marketing Automation for WooCommerce <= 2.6.14
References
CVSS V3.1
Timeline
Vulnerability published