Vulnerability
Stored Cross Site Scripting in FluentSMTP plugin prior to 2.2.2.
Description
The plugin has a functionality that allows the admin to view logs of all emails sent using wpmail function. No sanitization while rendering the email content leads to stored cross-site scripting.
CVE-ID
CVE-2023-0219
Vendor
WPManageNinja
Product
FluentSMTP prior to 2.2.2
Disclosure Timeline
Reported On: 10th January 2023
Made Public On: NA (yet to be made public)
Fixed On: NA (yet to be fixed)