What the vulnerability does
01Description
Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Nicolas Lemoine WP Better Emails plugin <= 0.4 versions.
CVSS base score
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:L
What the vulnerability does
Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Nicolas Lemoine WP Better Emails plugin <= 0.4 versions.
Explanation of Vulnerability in Simple Terms
WP Better Emails versions 0.4 and earlier contain a cross-site scripting (XSS) vulnerability. An authenticated administrator can inject malicious scripts through the plugin's interface. When another user views the affected content, the script executes in their browser, potentially compromising their session or stealing data. The vulnerability requires admin privileges and user interaction to exploit.
What an attacker can do
Inject malicious scripts that execute in other users' browsers when they view the plugin's interface.
Potential impact on your site
An admin account compromise could allow script injection affecting other site users and administrators.
Conditions required to exploit
Administrator account access and the victim must view a page containing the injected script.
Key dates
External resources
Related vulnerabilities