
In LetterPress plugin <= 1.2.1 is vulnerable to Cookie Stealing Vulnerability. An attacker can able to steal the cookies by injecting the JavaScript code.
https://nvd.nist.gov/vuln/detail/CVE-2024-34568 https://patchstack.com/database/wordpress/plugin/letterpress/vulnerability/wordpress-letterpress-newsletter-plugin-1-2-1-cross-site-scripting-xss-vulnerability
In LetterPress plugin <= 1.2.1 is vulnerable to Cookie Stealing Vulnerability. An attacker can able to steal the cookies by injecting the JavaScript code.
"" in HTML Campaign Message input field and click on Save Campaign.