The MailPoet plugin before 3.23.2 for WordPress allows remote attackers to inject arbitrary web script or HTML using extra parameters in the URL (Reflective Server-Side XSS).
History

Wed, 28 May 2025 14:45:00 +0000

Type Values Removed Values Added
First Time appeared Automattic
Automattic mailpoet
CPEs cpe:2.3:a:mailpoet:mailpoet:*:*:*:*:*:wordpress:*:* cpe:2.3:a:automattic:mailpoet:*:*:*:*:*:wordpress:*:*
Vendors & Products Mailpoet
Mailpoet mailpoet
Automattic
Automattic mailpoet

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published: 2020-06-02T16:45:17

Updated: 2024-08-04T23:03:32.884Z

Reserved: 2019-05-09T00:00:00

Link: CVE-2019-11843

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2020-06-02T17:15:11.627

Modified: 2025-05-28T14:29:39.447

Link: CVE-2019-11843

cve-icon Redhat

No data.