Lucene search

K
wpvulndb7cooWPVDB-ID:83ECA346-7045-414E-81FC-E0D9B735F0BD
HistoryMay 02, 2022 - 12:00 a.m.

Check & Log email < 1.0.6 - Reflected Cross-Site Scripting

2022-05-0200:00:00
7coo
wpscan.com
13
email security
plugin vulnerability
xss
admin page
software

EPSS

0.001

Percentile

40.2%

The plugin does not sanitise and escape a parameter before outputting it back in an attribute in an admin page, leading to a Reflected Cross-Site Scripting

PoC

https://example.com/wp-admin/admin.php?page=check-email-settings&amp;tab;=">

EPSS

0.001

Percentile

40.2%

Related for WPVDB-ID:83ECA346-7045-414E-81FC-E0D9B735F0BD