Input validation vulnerability in WP-EMail 2.67.2

The WP-EMail plugin for WordPress is vulnerable to Cross-Site Scripting in versions up to and including 2.67.2. Cross-Site Scripting is when attackers inject malicious code into a website, which can then be executed by the browser of an unsuspecting user. This vulnerability could allow unauthenticated attackers to inject arbitrary web scripts into a website, compromising the security of the website and any users who visit it. The vulnerability is due to the plugin not properly sanitizing user input and not properly escaping output.

Detected in:

WP-EMail fixed vulnerable versions: >= * <= 2.67.2

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.