CVE-2024-1589: SendPress Newsletters <= 1.23.11.6 - Admin+ Stored XSS via Form Settings
The SendPress Newsletters WordPress plugin through 1.23.11.6 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfilteredhtml capability is disallowed (for example in multisite setup)
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-1589?
CVE-2024-1589 is classified as a moderate severity vulnerability that could allow for stored cross-site scripting attacks.
How do I fix CVE-2024-1589?
To fix CVE-2024-1589, update the SendPress Newsletters plugin to the latest version beyond 1.23.11.6.
Who is affected by CVE-2024-1589?
CVE-2024-1589 affects all versions of SendPress Newsletters up to and including 1.23.11.6.
What type of attack can CVE-2024-1589 lead to?
CVE-2024-1589 can lead to stored cross-site scripting (XSS) attacks, potentially allowing attackers to inject malicious scripts.
Does CVE-2024-1589 affect non-admin users?
CVE-2024-1589 primarily affects high privilege users, such as admins, even when the unfiltered_html capability is disallowed.