nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2023-3081 CVE-2023-3081
HIGH
WP Mail Logging <= 1.11.1 - Unauthenticated Stored Cross-Site Scripting via Email
Record summary
CVE-2023-3081 has a selected CVSS score of 7.2 (high).
Description
The WP Mail Logging plugin for WordPress is vulnerable to Stored Cross-Site Scripting via email contents in versions up to, and including, 1.11.1 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. Note: An incomplete fix was released in 1.11.1.
Description source: CVE List
Exploitation context
CISA SSVC decision
ExploitationNone
AutomatableYes
Technical impactPartial
CISA Coordinator · SSVC 2.0.3 · Evaluated Feb 5, 2025 · Source: CVE List
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
WP Mail LoggingBrowse smub / WP Mail LoggingDefault status: unaffected | CVE List | Through 1.11.1 | affected |
References
4plugins.trac.wordpress.org
https://plugins.trac.wordpress.org/changeset/2923464/wp-mail-logging plugins.trac.wordpress.org
https://plugins.trac.wordpress.org/changeset/2925728/wp-mail-logging wordfence.com
https://www.wordfence.com/threat-intel/vulnerabilities/id/ef20b3e6-d8f4-458e-b604-b46ef16e229e?source=cve