CVE-2022-1889
20.06.2022, 11:15
The Newsletter WordPress plugin before 7.4.6 does not escape and sanitise the preheader_text setting, which could allow high privilege users to perform Stored Cross-Site Scripting attacks when the unfilteredhtml is disallowed
Vendor | Product | Version |
---|---|---|
thenewsletterplugin | newsletter | 𝑥 < 7.4.6 |
𝑥
= Vulnerable software versions