Input validation vulnerability in Email Template Designer – WP HTML Mail 2.9.1

The WP HTML Mail plugin for WordPress is vulnerable to HTML injection. This means that unauthenticated attackers can inject arbitrary HTML into pages that would be executed. In order to do this, they must first trick an administrator into performing an action, such as clicking on a link. This vulnerability affects versions up to and including 2.9.0.3, because input sanitization is not enough.

Detected in:

Email Template Designer – WP HTML Mail fixed vulnerable versions: >= * < 2.9.1

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.