CVE-2024-43126: Sender – Newsletter, Sms And Email Marketing Automation For Woocommerce

High severity, CVSS 7.1. EPSS: 0.3% chance of exploitation in the next 30 days.

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Sender Sender – Newsletter, SMS and Email Marketing Automation for WooCommerce allows Reflected XSS.This issue affects Sender – Newsletter, SMS and Email Marketing Automation for WooCommerce: from n/a through 2.6.14.

Affected products

  • Sender Sender – Newsletter, Sms And Email Marketing Automation For Woocommerce: up to and including 2.6.14

Published 2024-08-12. Last modified 2026-06-17.