WordPress Plugin Vulnerabilities

Mail Queue < 1.2 - Unauthenticated Stored Cross-Site Scripting

Description

The plugin does not properly sanitize and escape user input for the email subject field. This can lead to the injection of arbitrary web scripts that execute whenever a page is accessed.

Affects Plugins

References

Classification

Type
XSS
CWE
CVSS

Miscellaneous

Original Researcher
Alex Thomas
Verified
No

Timeline

Publicly Published
2023-06-22 (about 2 years ago)
Added
2023-07-12 (about 2 years ago)
Last Updated
2023-07-12 (about 2 years ago)

Other