PT-2026-20632 · WordPress · Postmarkapp Email Integrator

Bhumividh Treloges

·

Publicado

2026-02-19

·

Atualizado

2026-02-19

·

CVE-2026-1043

CVSS v3.1

4.4

Média

VetorAV:N/AC:H/PR:H/UI:N/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions PostmarkApp Email Integrator plugin for WordPress versions up to and including 2.4
Description The PostmarkApp Email Integrator plugin for WordPress is susceptible to Stored Cross-Site Scripting. This is caused by inadequate input sanitization and output escaping of the pma api key and pma sender address parameters within the plugin settings. An authenticated attacker with Administrator-level access or higher can inject malicious web scripts that execute when users access the settings page.
Recommendations Update the PostmarkApp Email Integrator plugin to a version newer than 2.4.

Correção

XSS

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2026-1043

Produtos afetados

Postmarkapp Email Integrator