Vulnerability
FluentSMTP <= 2.2.2 Stored XSS via Email Logs
Description
The plugin does not sanitize or escape email content, making it vulnerable to stored cross-site scripting attacks (XSS) when an administrator views the email logs. This exploit requires other plugins to enable users to send emails with unfiltered HTML.
CVE-ID
CVE-2023-0219
Vendor
FluentSMTP & WPManageNinja Team
Product
FluentSMTP
Disclosure Timeline
Reported On: 10-01-23
Made Public On: 20-02-2023
Fixed On: 04-02-2023