CVE-2023-41729: WordPress SendPress Newsletters plugin <= 1.26.1.20 - Cross Site Scripting (XSS) vulnerability
Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in SendPress Newsletters plugin <= 1.22.3.31 versions.
Other sources
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in brewlabs SendPress Newsletters sendpress allows DOM-Based XSS.This issue affects SendPress Newsletters: from n/a through <= 1.26.1.20.
— MITRE
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID for this vulnerability?
The vulnerability ID for this vulnerability is CVE-2023-41729.
What plugin versions are affected by this vulnerability?
The SendPress Newsletters plugin versions up to and including 1.22.3.31 are affected by this vulnerability.
What is the severity of CVE-2023-41729?
The severity of CVE-2023-41729 is medium, with a severity value of 4.8.
What is the description of CVE-2023-41729?
CVE-2023-41729 is an Authentication (admin+) Stored Cross-Site Scripting (XSS) vulnerability in the SendPress Newsletters plugin.
How can I fix CVE-2023-41729?
To fix CVE-2023-41729, it is recommended to update the SendPress Newsletters plugin to a version higher than 1.22.3.31.