Vulnerabilities > Yaycommerce > Yaysmtp > 2.2.8

DATE CVE VULNERABILITY TITLE RISK
2023-07-12 CVE-2023-3093 Cross-site Scripting vulnerability in Yaycommerce Yaysmtp
The YaySMTP plugin for WordPress is vulnerable to Stored Cross-Site Scripting via email contents in versions up to, and including, 2.4.5 due to insufficient input sanitization and output escaping.
network
low complexity
yaycommerce CWE-79
6.1