CVE · Medium

CVE-2023-6621 — Post SMTP – Complete Email Deliverability and SMTP Solution with Email Logs, Alerts, Backup SMTP & Mobile App [post-smtp] < 2.8.7

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2023-6621 Post SMTP – Complete Email Deliverability and SMTP Solution with Email Logs, Alerts, Backup SMTP & Mobile App [post-smtp] < 2.8.7 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Medium 6.1 < 2.8.7 2.8.7 2024-01-03

CVE-2023-6621

The Post SMTP plugin versions prior to 2.8.7 contain a reflected cross-site scripting vulnerability due to inadequate sanitization and escaping of the msg parameter before it is displayed on the page. An attacker could exploit this flaw by crafting a malicious link to target high-privilege users like administrators and execute arbitrary JavaScript in their browsers. Upgrading to version 2.8.7 or later resolves this security issue.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.