CVSS 3.1 Score 6.1 of 10 (medium)


Published Nov 27, 2023
Updated: Dec 2, 2023


CVE-2023-5958 is a vulnerability in the POST SMTP Mailer WordPress plugin before version 2.7.1. The vulnerability allows an unauthenticated attacker to perform cross-site scripting (XSS) attacks against highly privileged users by exploiting the plugin's failure to escape email message content before displaying it in the backend. This vulnerability affects various products, including oQunGx, oQunHw, oQunHx, t0YY4i, and others. The risk score for this vulnerability is 26, with a base severity of MEDIUM. To remediate this issue, users should update the POST SMTP Mailer plugin to version 2.7.1 or later. The potential danger of this vulnerability is that it can allow attackers to inject malicious code into emails and potentially compromise the security of an organization's WordPress site, leading to unauthorized access or data theft.


Explore Beyond the CVE Basics with Recorded Future's Vulnerability Intelligence

Note: This is just a basic overview providing quick insights into CVE-2023-5958 information. Gain full access to comprehensive CVE data, risk scores, prioritization, and mitigation data through Recorded Future's Vulnerability Intelligence:
  • Prioritize with Risk-Based Scoring
  • Explore the Extensive Vulnerability Database
  • Receive Early Alerts on Emerging CVEs
  • Focus on Critical Exploitable Vulnerabilities
  • Streamline Remediation with Integration Options