{"id":"CVE-2019-11843","details":"The MailPoet plugin before 3.23.2 for WordPress allows remote attackers to inject arbitrary web script or HTML using extra parameters in the URL (Reflective Server-Side XSS).","modified":"2026-08-14T09:05:30.447909Z","published":"2020-06-02T17:15:11.627Z","references":[{"type":"ADVISORY","url":"https://github.com/mailpoet/mailpoet/releases/tag/3.23.2"},{"type":"ADVISORY","url":"https://pluginarchive.com/wordpress/mailpoet/v/3-23-2"},{"type":"ADVISORY","url":"https://wordpress.org/plugins/mailpoet/#developers"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/mailpoet/mailpoet","events":[{"introduced":"0"},{"fixed":"8d2d2719695fb0683ee3893cca8f7070986124c8"}],"database_specific":{"extracted_events":[{"introduced":"0"},{"fixed":"3.23.2"}],"source":["CPE_RANGE","REFERENCES"],"cpe":"cpe:2.3:a:automattic:mailpoet:*:*:*:*:*:wordpress:*:*"}}],"versions":["3.23.1","3.23.0","3.21.1","3.21.0","3.19.3","3.19.2","3.19.0","3.18.2","3.18.1","3.17.2","3.16.3","3.17.1","3.17.0","3.16.2","3.15.0","3.14.0","3.12.1","3.12.0","3.11.3","3.11.2","3.11.1","3.11.0","3.10.1","3.10","3.9.1","3.9.0","3.8.6","3.8.5","3.8.4","3.8.3","3.8.2","3.8.1","3.8","3.7.8","3.7.7","3.7.6","3.7.5","3.7.4","3.7.3","3.7.1","3.7.2","3.7.0","3.6.7","3.6.6","3.6.5","3.6.4","3.6.3","3.6.2","3.6.1","3.6.0","3.5.1","3.5.0","3.4.4","3.4.3","3.4.2","3.4.1","3.4.0","3.3.6","3.3.5","3.3.4","3.3.3","3.3.2","3.3.1","3.3.0","3.2.5","3.2.4","3.2.3","3.2.2","3.2.1","3.2.0","3.1.0","3.0.9","3.0.8","3.0.7","3.0.6","3.0.5","3.0.4","3.0.3","3.0.2","3.0.1","3.0.0","3.0.0-rc.2.0.3","3.0.0-rc.2.0.2","3.0.0-rc.2.0.1","3.0.0-rc.2.0.0","3.0.0-rc.1.0.4","3.0.0-rc.1.0.3","3.0.0-rc.1.0.2","3.0.0-rc.1.0.1","3.0.0-rc.1.0.0","3.0.0-beta.37.0.0","3.0.0-beta.36.3.1","3.0.0-beta.36.3.0","3.0.0-beta.36.2.0","3.0.0-beta.36.1.0","3.0.0-beta.36.0.1","3.0.0-beta.36.0.0","3.0.0-beta.35.0.0","3.0.0-beta.34.0.0","3.0.0-beta.33.1","3.0.0-beta.33","3.0.0-beta.32","3.0.0-beta.31","3.0.0-beta.30","3.0.0-beta.29","3.0.0-beta.28","3.0.0-beta.27","3.0.0-beta.26","3.0.0-beta.25","3.0.0-beta.24","3.0.0-beta.23.2","3.0.0-beta.23.1","3.0.0-beta.23","3.0.0-beta.22","3.0.0-beta.21","3.0.0-beta.20","3.0.0-beta.19","3.0.0-beta.18","3.0.0-beta.17","3.0.0-beta.16","3.0.0-beta.15","3.0.0-beta.14","3.0.0-beta.13","3.0.0-beta.12","3.0.0-beta.11","3.0.0-beta.10","3.0.0-beta.9","3.0.0-beta.8","3.0.0-beta.7.1","3.0.0-beta.7","3.0.0-beta.6","3.0.0-beta.5","3.0.0-beta.4","3.0.0-beta.3","3.0.0-beta.2","3.0.0-beta.1","0.0.50","0.0.49","0.0.48","0.0.47","0.0.46","0.0.45","0.0.44","0.0.43","0.0.42","0.0.41","0.0.40","0.0.39","0.0.38","0.0.37","0.0.36","0.0.35","0.0.34","0.0.33","0.0.32","0.0.31","0.0.30","0.0.29","0.0.28","0.0.27","0.0.26","0.0.25","0.0.24","0.0.23","0.0.22","0.0.21","0.0.20","0.0.19","0.0.18","0.0.17","0.0.16","0.0.15","0.0.14","0.0.13","0.0.12","0.0.11","0.0.10","0.0.9","0.0.8","0.0.7","0.0.6","0.0.5","0.0.4","0.0.3","0.0.2","0.0.1"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2019-11843.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N"}]}