CVE-2024-29128: WordPress POST SMTP Mailer plugin <= 2.8.6 - Reflected Cross Site Scripting (XSS) vulnerability
Published Mar 19, 2024
·Updated
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Post SMTP POST SMTP allows Reflected XSS.This issue affects POST SMTP: from n/a through 2.8.6.
Affected Software
3 affected components
Post SMTP Post SMTP<=2.8.6
WordPress POST SMTP Mailer<=2.8.6
Wpexperts Post Smtp Wordpress<2.8.7
Remediation
Information
Update to 2.8.7 or a higher version.
Event History
Mar 19, 2024
CVE Published
via MITRE·02:04 PM
Data Sourced
via MITRE·02:04 PM
RemedyDescriptionSeverityWeakness
Data Sourced
via NVD·02:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2024-29128?
CVE-2024-29128 is classified as a reflected cross-site scripting (XSS) vulnerability.
2
How do I fix CVE-2024-29128?
To fix CVE-2024-29128, update Post SMTP to version 2.8.7 or later.
3
Who is affected by CVE-2024-29128?
CVE-2024-29128 affects users of Post SMTP plugin versions up to 2.8.6.
4
What type of vulnerability is CVE-2024-29128?
CVE-2024-29128 is an improper neutralization of input during web page generation vulnerability.
5
Can CVE-2024-29128 lead to security issues?
Yes, CVE-2024-29128 can potentially allow attackers to execute arbitrary JavaScript in the context of the user's browser.