HTML Injection Vulnerability in Email Templates Plugin for WordPress
CVE-2019-25150
8.8HIGH
Key Information:
- Vendor
Wordpress
- Vendor
- CVE Published:
- 7 June 2023
What is CVE-2019-25150?
The Email Templates plugin for WordPress is susceptible to HTML Injection vulnerabilities that allow attackers to inject malicious HTML code. This can enable them to present deceptive phishing forms or execute Cross-Site Request Forgery (CSRF) attacks on unsuspecting site administrators. Versions up to and including 1.3 are affected, posing serious security risks. Website owners are advised to upgrade or apply necessary patches to mitigate exposure to these threats.
Affected Version(s)
Email Templates Customizer and Designer for WordPress and WooCommerce * <= 1.3