Input validation vulnerability in SendPress Newsletters 1.22.3.31

The SendPress Newsletters plugin for WordPress is vulnerable to a type of attack that can allow malicious users to inject web scripts into pages on the site. This attack is only possible if the plugin is installed in certain configurations, such as a multi-site installation or installation where user input is filtered. The plugin version 1.22.3.31 and earlier are vulnerable to this type of attack.

Detected in:

SendPress Newsletters open vulnerable versions: >= * <= 1.23.11.6

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.