Mailjet Email Marketing <= 5.3 - Authenticated (Admin+) Cross-Site Scripting
mediumThe Mailjet Email Marketing plugin for WordPress is vulnerable to authenticated stored cross-site scripting in versions up to, and including, 5.3 via the 'mailjet_from_name' parameter. This allows authenticated attackers with administrator-level capabilities to inject arbitrary web scripts in pages that will execute wh...
- CVSS:
- 5.5
- Affected:
- up to 5.3
- Fixed in:
- 5.3.1
- Disclosed:
- Jan 3, 2023