Medium severity6.1NVD Advisory· Published Oct 21, 2021· Updated Jun 17, 2026
CVE-2021-28975
CVE-2021-28975
Description
WP Mailster 1.6.18.0 allows XSS when a victim opens a mail server's details in the mst_servers page, for a crafted server_host, server_name, or connection_parameter parameter.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
3- cpe:2.3:a:wpmailster:wp_mailster:1.6.18:*:*:*:*:wordpress:*:*
- WP Mailster/WP Mailsterdescription
Patches
Vulnerability mechanics
References
2- www.compass-security.com/fileadmin/Research/Advisories/2021-18_CSNC-2021-018-WPMailster_XSS_CSRF.txtnvdExploitThird Party Advisory
- www.compass-security.com/en/research/advisories/nvdThird Party Advisory
News mentions
0No linked articles in our index yet.