Vulnerabilities > Wpexperts > Post Smtp > 2.8.3
DATE | CVE | VULNERABILITY TITLE | RISK |
---|---|---|---|
2024-01-03 | CVE-2023-6621 | Cross-site Scripting vulnerability in Wpexperts Post Smtp The POST SMTP WordPress plugin before 2.8.7 does not sanitise and escape the msg parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin. | 6.1 |
2024-01-03 | CVE-2023-6629 | Cross-site Scripting vulnerability in Wpexperts Post Smtp The POST SMTP Mailer – Email log, Delivery Failure Notifications and Best Mail SMTP for WordPress plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘msg’ parameter in all versions up to, and including, 2.8.6 due to insufficient input sanitization and output escaping. | 6.1 |
2024-01-03 | CVE-2023-7027 | Cross-site Scripting vulnerability in Wpexperts Post Smtp The POST SMTP Mailer – Email log, Delivery Failure Notifications and Best Mail SMTP for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘device’ header in all versions up to, and including, 2.8.7 due to insufficient input sanitization and output escaping. | 5.4 |