Vulnerability Description
The POST SMTP Mailer WordPress plugin before 2.7.1 does not escape email message content before displaying it in the backend, allowing an unauthenticated attacker to perform XSS attacks against highly privileged users.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Wpexperts | Post Smtp | < 2.7.1 |
Related Weaknesses (CWE)
References
- https://wpscan.com/vulnerability/22fa478d-e42e-488d-9b4b-a8720dec7ceeExploitThird Party Advisory
- https://wpscan.com/vulnerability/22fa478d-e42e-488d-9b4b-a8720dec7ceeExploitThird Party Advisory
FAQ
What is CVE-2023-5958?
CVE-2023-5958 is a vulnerability with a CVSS score of 6.1 (MEDIUM). The POST SMTP Mailer WordPress plugin before 2.7.1 does not escape email message content before displaying it in the backend, allowing an unauthenticated attacker to perform XSS attacks against highly...
How severe is CVE-2023-5958?
CVE-2023-5958 has been rated MEDIUM with a CVSS base score of 6.1/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2023-5958?
Check the references section above for vendor advisories and patch information. Affected products include: Wpexperts Post Smtp.