CVE-2023-41736: WordPress Email posts to subscribers Plugin <= 6.2 is vulnerable to Cross Site Scripting (XSS)
Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Gopi Ramasamy Email posts to subscribers plugin <= 6.2 versions.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2023-41736?
The severity of CVE-2023-41736 is medium.
How does the Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability occur in Gopi Ramasamy Email posts to subscribers plugin versions up to and including 6.2?
The vulnerability occurs due to insufficient input sanitization in the plugin, allowing an authenticated administrator or higher privileged user to inject malicious scripts into posts that will be executed when viewed by subscribers.
What is the affected software of CVE-2023-41736?
The affected software is Gopi Ramasamy Email posts to subscribers plugin versions up to and including 6.2 for WordPress.
How can I fix the Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Gopi Ramasamy Email posts to subscribers plugin versions up to and including 6.2?
To fix the vulnerability, it is recommended to update to a patched version of Gopi Ramasamy Email posts to subscribers plugin that addresses the XSS vulnerability. Additionally, input sanitization should be implemented to ensure user-generated content is properly sanitized.
What is the Common Weakness Enumeration (CWE) ID for CVE-2023-41736?
The Common Weakness Enumeration (CWE) ID for CVE-2023-41736 is CWE-79 (Cross-Site Scripting).