HomeDefault status
unaffected
Any version before 2.0.13
affected
Description
The Check & Log Email WordPress plugin before 2.0.13 does not properly handle email replacement, which could allow unauthenticated users to perform Stored XSS attacks when the email encoder setting is enabled
Problem types
CWE-79 Cross-Site Scripting (XSS)
Product status
Any version before 2.0.13
Credits
Matthew Rollings
WPScan
References
wpscan.com/...rability/97908c15-6e7a-4242-8c6f-66c8b804364c/