Lucene search

K
wpvulndbWpvulndbWPVDB-ID:B0E7665A-C8C3-4132-B8D7-8677A90118DF
HistoryMay 15, 2023 - 12:00 a.m.

Newsletter, SMTP, Email marketing and Subscribe forms by Sendinblue < 3.1.61 - Reflected XSS

2023-05-1500:00:00
wpscan.com
5
newsletter plugin
smtp
email marketing
sendinblue
reflected xss
admin dashboard
wpml plugin
admin privilege

0.001 Low

EPSS

Percentile

24.8%

The plugin does not sanitise and escape a parameter before outputting it back in the admin dashboard when the WPML plugin is also active and configured, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin

PoC

Make a logged in admin open a page containing the code below (the WPML, slug: sitepress-multilingual-cms, needs to be active and configured as well. The ID is a translated form ID)

CPENameOperatorVersion
mailinlt3.1.61

0.001 Low

EPSS

Percentile

24.8%

Related for WPVDB-ID:B0E7665A-C8C3-4132-B8D7-8677A90118DF