CVE-2022-2351
16.09.2022, 09:15
The Post SMTP Mailer/Email Log WordPress plugin before 2.1.4 does not escape some of its settings before outputting them in the admins dashboard, allowing high privilege users to perform Cross-Site Scripting attacks against other users even when the unfiltered_html capability is disallowed.
Vendor | Product | Version |
---|---|---|
wpexperts | post_smtp | 𝑥 < 2.1.4 |
𝑥
= Vulnerable software versions