CVE-2022-2371: YaySMTP < 2.2.1 - Subscriber+ Stored Cross-Site Scripting
Published Aug 8, 2022
·Updated
The YaySMTP WordPress plugin before 2.2.1 does not have proper authorisation when saving its settings, allowing users with a role as low as subscriber to change them, and use that to conduct Stored Cross-Site Scripting attack due to the lack of escaping in them as well.
Affected Software
1 affected component
Yaycommerce Yaysmtp Wordpress<2.2.1
Event History
Aug 8, 2022
CVE Published
via MITRE·01:47 PM
Data Sourced
via MITRE·01:47 PM
DescriptionWeakness
Frequently Asked Questions
1
What is the vulnerability ID for the YaySMTP WordPress plugin?
The vulnerability ID for the YaySMTP WordPress plugin is CVE-2022-2371.
2
What is the severity of CVE-2022-2371?
The severity of CVE-2022-2371 is medium with a CVSS score of 5.4.
3
What is the affected software for CVE-2022-2371?
The affected software for CVE-2022-2371 is the YaySMTP WordPress plugin before version 2.2.1.
4
What type of vulnerability is CVE-2022-2371?
CVE-2022-2371 is a Stored Cross-Site Scripting (XSS) vulnerability.
5
How can I fix the vulnerability in the YaySMTP WordPress plugin?
To fix the vulnerability in the YaySMTP WordPress plugin, update to version 2.2.1 or newer.