CVE-2022-1889: Newsletter < 7.4.6 - Admin+ Stored Cross-Site Scripting
Published Jun 20, 2022
·Updated
The Newsletter WordPress plugin before 7.4.6 does not escape and sanitise the preheadertext setting, which could allow high privilege users to perform Stored Cross-Site Scripting attacks when the unfilteredhtml is disallowed
Affected Software
1 affected component
Thenewsletterplugin Newsletter Wordpress<7.4.6
Event History
Jun 20, 2022
CVE Published
via MITRE·10:26 AM
Data Sourced
via MITRE·10:26 AM
DescriptionWeakness
Frequently Asked Questions
1
What is the vulnerability ID for this issue?
The vulnerability ID for this issue is CVE-2022-1889.
2
What is the severity of CVE-2022-1889?
The severity of CVE-2022-1889 is medium, with a severity value of 4.8.
3
What is the affected software?
The affected software is the Newsletter WordPress plugin before version 7.4.6.
4
What is the impact of this vulnerability?
This vulnerability could allow high privilege users to perform Stored Cross-Site Scripting (XSS) attacks when the unfilteredhtml is disallowed.
5
How can I fix CVE-2022-1889?
To fix CVE-2022-1889, update your Newsletter WordPress plugin to version 7.4.6 or later.