WordPress Plugin Vulnerabilities
WP Mail Logging < 1.17.0 - Unauthenticated HTML Injection
Description
The plugin does not properly restrict the HTML and CSS of logged emails before rendering them in its admin log screens, allowing unauthenticated users to inject styled content and links, for example through a public contact form, that can deceive an administrator viewing the log and send their browser to an attacker-controlled page.
Proof of Concept
Affects Plugins
References
CVE
Classification
Type
INJECTION
OWASP top 10
CVSS
Miscellaneous
Original Researcher
Kasia Sok
Submitter
Kasia Sok
Verified
Yes
WPVDB ID
Timeline
Publicly Published
2026-09-28 (about 4 days ago)
Added
2026-09-28 (about 3 days ago)
Last Updated
2026-09-28 (about 3 days ago)