← Back
Web Application
CVE-2026-16636 high CVSS 7.2

The FluentSMTP – WP SMTP Plugin with Amazon SES, SendGrid, MailGun, Postmark, Google and Any SMTP...

Summary

The FluentSMTP – WP SMTP Plugin with Amazon SES, SendGrid, MailGun, Postmark, Google and Any SMTP...

AI summary openai / gpt-4o

FluentSMTPプラグインは、受信者表示名を介した保存型クロスサイトスクリプティング(XSS)に対して脆弱です。この脆弱性は、不十分な入力サニタイズと出力エスケープに起因します。攻撃者は、管理者が詳細ビューを使用する際に実行されるスクリプトを注入可能です。
❓ What is the problem
FluentSMTPプラグインでの保存型XSS脆弱性
📍 Affected scope
バージョン2.2.95以下のFluentSMTPプラグイン
🔥 Severity
認証されていない攻撃者が任意のスクリプトを管理者に対して実行可能
🔧 How to fix
入力を適切にサニタイズし、出力をエスケープすること
🛡️ Workaround
詳細ビューでの閲覧を避ける
🔍 Detection
影響を受ける場合、管理者が詳細ビューを使用した際、意図しないスクリプト実行を確認する

References

🍪 About cookies

We use cookies to keep you logged in, remember your language, and improve the service.

Details →