Description
A stored cross site scripting (XSS) vulnerability in phplist 3.5.4 and below allows attackers to execute arbitrary web scripts or HTML via a crafted payload in the "rule1" parameter under the "Bounce Rules" module.
Remediation
References
Related Vulnerabilities
WordPress Plugin Custom Post Type UI 'wp-admin/admin.php' Cross-Site Scripting (0.7)
Chamilo Authorization Bypass Through User-Controlled Key Vulnerability (CVE-2026-33702)
WordPress Plugin Secure HTML5 Video Player Cross-Site Scripting (3.3)
WordPress Plugin JW Player for Flash & HTML5 Video Cross-Site Request Forgery (2.1.11)