CVE Database
/

CVE-2022-1889

Back to search

CVE-2022-1889

Published: Jun 20, 2022

Modified: Aug 3, 2024

PUBLISHED

Description

The Newsletter WordPress plugin before 7.4.6 does not escape and sanitise the preheader_text setting, which could allow high privilege users to perform Stored Cross-Site Scripting attacks when the unfilteredhtml is disallowed

VendorProductVersions

Unknown

Newsletter – Send awesome emails from WordPress

affected
7.4.6 - < 7.4.6

Weaknesses (CWE)

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now