CVE-2021-24528

CVE-2021-24528: FluentSMTP < 2.0.1 - Authenticated Stored XSS

Vendor Unknown
Product FluentSMTP – WordPress Mail SMTP, SES, SendGrid, Mailgun and Any SMTP Plugin
Weakness CWE-79 · XSS
Published August 30, 2021
Last update August 3, 2024

CVSS base score

What the vulnerability does

01Description

The FluentSMTP WordPress plugin before 2.0.1 does not sanitize parameters before storing the settings in the database, nor does the plugin escape the values before outputting them when viewing the SMTP settings set by this plugin, leading to a stored cross site scripting (XSS) vulnerability. Only users with roles capable of managing plugins can modify the plugin's settings.

Key dates

02Disclosure timeline

August 30, 2021 CVE published
August 3, 2024 Record updated