Entreprise d'experts en Sécurité Informatique : Audits et conseils en cybersécurité
Entreprise française de cybersécurité depuis 2004
☎ 03 60 47 09 81 - info@securiteinfo.com


CVE-2023-5958

Description

The POST SMTP Mailer WordPress plugin before 2.7.1 does not escape email message content before displaying it in the backend, allowing an unauthenticated attacker to perform XSS attacks against highly privileged users.

POC

Reference

- https://wpscan.com/vulnerability/22fa478d-e42e-488d-9b4b-a8720dec7cee

Github

- https://github.com/20142995/nuclei-templates

- https://github.com/afine-com/research