CVE-2024-29128: WordPress POST SMTP Mailer plugin <= 2.8.6 - Reflected Cross Site Scripting (XSS) vulnerability
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Post SMTP POST SMTP allows Reflected XSS.This issue affects POST SMTP: from n/a through 2.8.6.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
WordPress POST SMTP Mailer pluginto a version that resolves this vulnerability.Fixed in 2.8.7
Event History
Frequently Asked Questions
What is the severity of CVE-2024-29128?
CVE-2024-29128 is classified as a reflected cross-site scripting (XSS) vulnerability.
How do I fix CVE-2024-29128?
To fix CVE-2024-29128, update Post SMTP to version 2.8.7 or later.
Who is affected by CVE-2024-29128?
CVE-2024-29128 affects users of Post SMTP plugin versions up to 2.8.6.
What type of vulnerability is CVE-2024-29128?
CVE-2024-29128 is an improper neutralization of input during web page generation vulnerability.
Can CVE-2024-29128 lead to security issues?
Yes, CVE-2024-29128 can potentially allow attackers to execute arbitrary JavaScript in the context of the user's browser.