HTML Injection Vulnerability in Email Templates Plugin for WordPress
CVE-2019-25150

8.8HIGH

Key Information:

Summary

The Email Templates plugin for WordPress is susceptible to HTML Injection vulnerabilities that allow attackers to inject malicious HTML code. This can enable them to present deceptive phishing forms or execute Cross-Site Request Forgery (CSRF) attacks on unsuspecting site administrators. Versions up to and including 1.3 are affected, posing serious security risks. Website owners are advised to upgrade or apply necessary patches to mitigate exposure to these threats.

Affected Version(s)

Email Templates Customizer and Designer for WordPress and WooCommerce * <= 1.3

References

CVSS V3.1

Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Jerome Bruandet
.