HTML Injection Vulnerability in Email Templates Plugin for WordPress
CVE-2019-25150
Key Information:
- Vendor
Wordpress
- Vendor
- CVE Published:
- 7 June 2023
What is CVE-2019-25150?
The Email Templates plugin for WordPress is susceptible to HTML Injection vulnerabilities that allow attackers to inject malicious HTML code. This can enable them to present deceptive phishing forms or execute Cross-Site Request Forgery (CSRF) attacks on unsuspecting site administrators. Versions up to and including 1.3 are affected, posing serious security risks. Website owners are advised to upgrade or apply necessary patches to mitigate exposure to these threats.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
Email Templates Customizer and Designer for WordPress and WooCommerce * <= 1.3
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved