First published: Mon Aug 08 2022(Updated: )
The YaySMTP WordPress plugin before 2.2.2 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks when the unfiltered_html capability is disallowed (for example in multisite setup)
Credit: contact@wpscan.com
Affected Software | Affected Version | How to fix |
---|---|---|
Yaycommerce | <2.2.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2022-2372 is a vulnerability in the YaySMTP WordPress plugin before version 2.2.2 that allows high privilege users to perform Stored Cross-Site Scripting attacks.
CVE-2022-2372 affects YaySMTP plugin before version 2.2.2 by not sanitising and escaping some of its settings, which can be exploited by high privilege users.
The severity of CVE-2022-2372 is medium with a CVSS score of 4.8.
To fix CVE-2022-2372, update YaySMTP WordPress plugin to version 2.2.2 or higher.
Stored Cross-Site Scripting (XSS) attack is a type of security vulnerability that allows an attacker to inject malicious scripts into web pages and have them executed by other users.