Cross-Site Request Forgery in WP Email Template by WordPress
CVE-2025-58800

4.3MEDIUM

Key Information:

Vendor

WordPress

Vendor
CVE Published:
5 September 2025

What is CVE-2025-58800?

The WP Email Template plugin contains a Cross-Site Request Forgery (CSRF) vulnerability that allows attackers to perform unauthorized actions on behalf of authenticated users. This security flaw can lead to significant risks if exploited, as malicious actors can execute requests without the user's knowledge. The affected versions range from n/a to 2.8.3, making it crucial for users to upgrade to secure their installations.

Affected Version(s)

WP Email Template <= 2.8.3

References

CVSS V3.1

Score:
4.3
Severity:
MEDIUM
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Nguyen Xuan Chien (Patchstack Alliance)
.