Input validation vulnerability in SendPress Newsletters 1.23.11.6

The SendPress Newsletters plugin for WordPress contains a security vulnerability that could allow unauthenticated attackers to inject malicious web scripts into pages. This vulnerability is present in all versions of the plugin up to, and including, version 1.23.11.6 and is caused by a lack of proper sanitization and output escaping of user input. If an attacker is successful in tricking a user into clicking on a malicious link, these web scripts could be executed.

Detected in:

SendPress Newsletters open vulnerable versions: >= * <= 1.23.11.6

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.