← Back to CVE List

CVE-2023-5958

Published: 2023-11-27T17:15Z
Last Modified: 2024-11-21T08:42Z
Source: MITRE CVE List
License: MITRE-CVE-TOS
The POST SMTP Mailer WordPress plugin before 2.7.1 does not escape email message content before displaying it in the backend, allowing an unauthenticated attacker to perform XSS attacks against highly privileged users. > MITRE Terms of Use apply – see LICENSE‑MITRE.txt