Input validation vulnerability in AcyMailing – Newsletter & mailing automation for WordPress 8.6.2

The AcyMailing SMTP Newsletter plugin for WordPress is not secure in versions 8.6.2 and below. Attackers who are not authenticated can inject malicious web scripts into pages which can be triggered if a user performs certain actions, such as clicking a link. These scripts can be used to harm the user and the website. To prevent this, the plugin must be updated to the latest version.

Detected in:

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.