What the vulnerability does
01Description
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in PillarDev Easy Automatic Newsletter Lite easy-automatic-newsletter allows Reflected XSS.This issue affects Easy Automatic Newsletter Lite: from n/a through <= 3.2.0.
Explanation of Vulnerability in Simple Terms
02Summary
Easy Automatic Newsletter Lite versions 3.2.0 and earlier contain a cross-site scripting (XSS) vulnerability. An attacker can inject malicious scripts that execute in a victim's browser when they visit a crafted page. The vulnerability requires user interaction and can affect other users or the site itself depending on context. Update to a version newer than 3.2.0 to resolve this issue.
What an attacker can do
03Attacker Capabilities
Inject malicious scripts that run in a victim's browser, potentially stealing session data or performing actions on their behalf.
Potential impact on your site
04Site Impact
Site visitors could be compromised; attackers may steal credentials, session tokens, or perform unauthorized actions as the victim.
Conditions required to exploit
05Prerequisites
Victim must visit a page containing the attacker's malicious input; no authentication required.
Key dates
06Disclosure timeline
March 3, 2025
CVE published
May 11, 2026
Record updated