Description
The mailSend function in the isMail transport in PHPMailer before 5.2.18 might allow remote attackers to pass extra parameters to the mail command and consequently execute arbitrary code via a \" (backslash double quote) in a crafted Sender property.
Remediation
References
Related Vulnerabilities
WordPress 3.1.2 Multiple Vulnerabilities (3.0.1 - 3.1.2)
WordPress Plugin Front File Manager 'upload.php' Arbitrary File Upload (0.1)
MySQL CVE-2020-14790 Vulnerability (CVE-2020-14790)
WordPress Plugin Daily Prayer Time Cross-Site Scripting (2021.08.07)
WordPress Plugin Order XML File Export Import for WooCommerce Cross-Site Request Forgery (1.3.0)