cleantalk
Vulnerabilities and Security Researches

weMail – Email Marketing, Newsletter, Optin Forms, Subscribers WordPress Plugin, CVE-2024-43238

CVE, Research URL

CVE-2024-43238

Published on
Aug 18, 2024
Research Description
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in weDevs weMail allows Reflected XSS.This issue affects weMail: from n/a through 1.14.5.
Affected versions
Min -, max 1.14.6.
Status
vulnerable