CVE-2024-11945

Published
View on NVD ↗
CVSS v3
6.4
MEDIUM
CVSS v2
N/A
Affected
1
PROJECT

Description

The Email Reminders plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘id’ parameter in all versions up to, and including, 2.0.4 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

<p>Reminders it&#8217;s ready to send emails, that was created based on Rules from specific Contacts.<br /> It can be emails that are sending before or after specific time to the event from Contact data.<br /> Like <strong>follow-up emails</strong> or <strong>friendly reminders</strong> about upcoming events.</p> <blockquote> <p><a href="https://oplugins.com/plugins/email-reminders" title="Email Reminders Homepage" rel="nofollow ugc">Plugin Homepage</a> | <a href="https://oplugins.com/plugins/email-reminders/#support" title="Support" rel="nofollow ugc">Support</a></p> </blockquote> <h4>FEATURES</h4> <h4>Reminders</h4> <ul> <li>Create and send email reminders and follow-up emails.</li> <li>Automatic sending of email reminders via CRON.</li> <li>Manually send specific email reminder(s) from admin panel.</li> <li>Listing and real time (ajax) text searching of specific email reminder at reminders page. You can easily send or delete certain reminder.</li> <li>You can filter reminders to show only sent or waiting to send emails reminders, or both.</li> <li>Checking the status near each reminder (sent or not sent), as well as the name of the email template that uses the specific email reminder.</li> </ul> <h4>Contacts</h4> <ul> <li>Easily create new contact based on customized contact form.</li> <li>Ability to import contacts from CSV files.</li> <li>Native integration with [Booking Calendar] (https://wordpress.org/plugins/booking/ &#8220;Booking Calendar&#8221;) plugin. Import all existing bookings. Create contacts in real time after creation of new bookings.</li> <li>Real time (ajax) text searching of specific contact.</li> <li>Ability to edit contact details and deletion of specific contacts.</li> </ul> <h4>Rules</h4> <ul> <li>Rules configuration for creation of new email-reminders from existing contacts based on multiple parameters. For example, creation new email-reminders from contacts, where country is USA, and date of creation of contact 7 days ago, etc&#8230;</li> <li>Configuration of time based parameters, which provide ability to configure rules, like: &#8220;reminder &#8211; 1 day before the event&#8221;, &#8220;follow-up email &#8211; 7 days after the event&#8221;, &#8220;after 1.5 months&#8221;, etc&#8230;</li> <li>Ability to create several email templates and select specific email template for specific rules for creation of email reminders.</li> <li>Manually run specific rule to create email reminders from admin panel.</li> <li>Automatic creation of email reminders via CRON.</li> <li>Ability to edit rule details and delete of specific rules.</li> <li> <p>If you have thousands of contacts, and you only need to handle the latest and not all together, you can define contact ID from which the rule will be executed.</p> </li> <li> <p>Mobile friendly.</p> </li> <li>Ajax based admin panel.</li> </ul> <h4>EMAIL REMINDERS IS GREAT FOR</h4> <ul> <li>Send <strong>friendly reminders</strong> about upcoming events.</li> <li>Send <strong>follow-up emails</strong> after specific action.</li> </ul>
WordPress Plugin DirectoryWordPress Plugin Directory
7.67K