HTML Injection Vulnerability in Email Templates Plugin for WordPress
CVE-2019-25150
8.8HIGH
Key Information:
- Vendor
- Wordpress
- Vendor
- CVE Published:
- 7 June 2023
Summary
The Email Templates plugin for WordPress is susceptible to HTML Injection vulnerabilities that allow attackers to inject malicious HTML code. This can enable them to present deceptive phishing forms or execute Cross-Site Request Forgery (CSRF) attacks on unsuspecting site administrators. Versions up to and including 1.3 are affected, posing serious security risks. Website owners are advised to upgrade or apply necessary patches to mitigate exposure to these threats.
Affected Version(s)
Email Templates Customizer and Designer for WordPress and WooCommerce * <= 1.3
References
CVSS V3.1
Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Jerome Bruandet