Stored XSS Vulnerability in Email Address Encoder Plugin by WordPress
CVE-2026-5305
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 25 June 2026
Badges
What is CVE-2026-5305?
The Email Address Encoder WordPress plugin versions prior to 1.0.25 and the email-encoder-premium WordPress plugin before version 0.3.12 exhibit security flaws in their email replacement functionality. This imperfection allows unauthenticated attackers to execute Stored Cross-Site Scripting (XSS) attacks, potentially compromising user data and site integrity by injecting malicious scripts that execute in the context of users who visit the affected web pages.
Affected Version(s)
Email Address Encoder 0 < 1.0.25
email-encoder-premium 0 < 0.3.12
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V3.1
Timeline
- ๐ก
Public PoC available
- ๐พ
Exploit known to exist
Vulnerability published
Vulnerability Reserved