Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-2r79-jc6j-hh65

Опубликовано: 27 нояб. 2023
Источник: github
Github: Не прошло ревью
CVSS3: 6.1

Описание

The POST SMTP Mailer WordPress plugin before 2.7.1 does not escape email message content before displaying it in the backend, allowing an unauthenticated attacker to perform XSS attacks against highly privileged users.

The POST SMTP Mailer WordPress plugin before 2.7.1 does not escape email message content before displaying it in the backend, allowing an unauthenticated attacker to perform XSS attacks against highly privileged users.

EPSS

Процентиль: 73%
0.00779
Низкий

6.1 Medium

CVSS3

Дефекты

CWE-79

Связанные уязвимости

CVSS3: 6.1
nvd
около 2 лет назад

The POST SMTP Mailer WordPress plugin before 2.7.1 does not escape email message content before displaying it in the backend, allowing an unauthenticated attacker to perform XSS attacks against highly privileged users.

EPSS

Процентиль: 73%
0.00779
Низкий

6.1 Medium

CVSS3

Дефекты

CWE-79