WordPress Plugin Vulnerabilities

Email Encoder < 2.2.2 - Admin+ Stored XSS

Description

The plugin does not escape the WP_Email_Encoder_Bundle_options[protection_text] parameter before outputting it back in an attribute in an admin page, leading to a Stored Cross-Site Scripting

Proof of Concept

Affects Plugins

Fixed in 2.2.2

References

Classification

Type
XSS
CWE
CVSS

Miscellaneous

Original Researcher
Krugov Artyom
Submitter
Krugov Aryom
Verified
Yes

Timeline

Publicly Published
2024-07-08 (about 1 year ago)
Added
2024-07-08 (about 1 year ago)
Last Updated
2024-07-08 (about 1 year ago)

Other