The Newsletter WordPress plugin prior to 7.4.6 does not escape and sanitise the preheader_text setting, which could allow high privilege users to perform Stored Cross-Site Scripting attacks when the unfilteredhtml is disallowed
Vulnerable Product | Search on Vulmon | Subscribe to Product |
---|---|---|
thenewsletterplugin newsletter |