CVE-2024-10103

In the process of testing the MailPoet WordPress plugin before 5.3.2, a vulnerability was found that allows you to implement Stored XSS on behalf of the editor by embedding malicious script, which entails account takeover backdoor
References
Configurations

Configuration 1 (hide)

cpe:2.3:a:automattic:mailpoet:*:*:*:*:free:wordpress:*:*

History

12 Jun 2025, 17:01

Type Values Removed Values Added
First Time Automattic
Automattic mailpoet
References () https://wpscan.com/vulnerability/89660883-5f34-426a-ad06-741c0c213ecc/ - () https://wpscan.com/vulnerability/89660883-5f34-426a-ad06-741c0c213ecc/ - Exploit, Third Party Advisory
CPE cpe:2.3:a:automattic:mailpoet:*:*:*:*:free:wordpress:*:*

19 Nov 2024, 15:35

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 6.1
CWE CWE-79
Summary
  • (es) En el proceso de prueba del complemento MailPoet para WordPress anterior a la versión 5.3.2, se encontró una vulnerabilidad que permite implementar XSS almacenado en nombre del editor mediante la incorporación de un script malicioso, lo que implica una puerta trasera de apropiación de cuentas.

19 Nov 2024, 06:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-11-19 06:15

Updated : 2025-06-12 17:01


NVD link : CVE-2024-10103

Mitre link : CVE-2024-10103

CVE.ORG link : CVE-2024-10103


JSON object : View

Products Affected

automattic

  • mailpoet
CWE
CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')