CVE-2026-1661
⚪ Do wiadomości
Brak odpowiednich ograniczeń w WP Mail Logging pozwala na wstrzyknięcie złośliwego HTML przez nieautoryzowanych użytkowników.
CVSS
4.3
EPSS
0.2%
Exploit
none
Vendor
Opis źródłowy (NVD)
The WP Mail Logging WordPress plugin before 1.17.0 does not properly restrict the HTML and CSS of logged emails before rendering them in its admin log screens, allowing unauthenticated users to inject styled content and links, for example through a public contact form, that can deceive an administrator viewing the log and send their browser to an attacker-controlled page.
brak
Brak patcha
Źródła i daty
| Źródło | Wartość |
|---|---|
| NVD – CVSS | 4.3 |
| CISA KEV (aktywnie wykorzystywane) | Nie |
| FIRST EPSS (prawdopodobieństwo exploita) | 0.2% |
| Opublikowano (NVD) | 2026-10-02 07:16:36 UTC |
| Ostatnia modyfikacja (NVD) | 2026-10-02 18:00:34 UTC |