CVE-2022-2372: YaySMTP < 2.2.2 - Admin+ Stored Cross-Site Scripting
The YaySMTP WordPress plugin before 2.2.2 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks when the unfilteredhtml capability is disallowed (for example in multisite setup)
Affected Software
Event History
Frequently Asked Questions
What is CVE-2022-2372?
CVE-2022-2372 is a vulnerability in the YaySMTP WordPress plugin before version 2.2.2 that allows high privilege users to perform Stored Cross-Site Scripting attacks.
How does CVE-2022-2372 affect YaySMTP?
CVE-2022-2372 affects YaySMTP plugin before version 2.2.2 by not sanitising and escaping some of its settings, which can be exploited by high privilege users.
What is the severity of CVE-2022-2372?
The severity of CVE-2022-2372 is medium with a CVSS score of 4.8.
How can I fix CVE-2022-2372?
To fix CVE-2022-2372, update YaySMTP WordPress plugin to version 2.2.2 or higher.
What is Stored Cross-Site Scripting (XSS) attack?
Stored Cross-Site Scripting (XSS) attack is a type of security vulnerability that allows an attacker to inject malicious scripts into web pages and have them executed by other users.