CVE-2024-1588: SendPress Newsletters <= 1.23.11.6 - Admin+ Stored XSS via Settings
The SendPress Newsletters WordPress plugin through 1.23.11.6 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfilteredhtml capability is disallowed (for example in multisite setup)
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-1588?
CVE-2024-1588 is classified as a high severity vulnerability due to its potential for Stored Cross-Site Scripting attacks.
How do I fix CVE-2024-1588?
To fix CVE-2024-1588, update the SendPress Newsletters plugin to version 1.23.11.7 or later, where the vulnerability is addressed.
Who is affected by CVE-2024-1588?
CVE-2024-1588 affects users of the SendPress Newsletters plugin version 1.23.11.6 and earlier.
What type of vulnerability is CVE-2024-1588?
CVE-2024-1588 is a Stored Cross-Site Scripting (XSS) vulnerability that allows the injection of malicious scripts.
Can unprivileged users exploit CVE-2024-1588?
No, only high privilege users, such as administrators, can exploit CVE-2024-1588 to perform attacks.