Description
An issue was discovered in phpList through 3.5.4. An XSS vulnerability occurs within the Import Administrators section via upload of an edited text document. This also affects the Subscriber Lists section.
Remediation
References
Related Vulnerabilities
WordPress Plugin All-in-One Event Calendar Multiple Cross-Site Scripting Vulnerabilities (1.5)
OpenSSL Use of a Broken or Risky Cryptographic Algorithm Vulnerability (CVE-2018-0734)
WordPress Plugin Email posts to subscribers Multiple Vulnerabilities (2.0)
WordPress Plugin WooCommerce PayPlug Unspecified Vulnerability (3.1.0)