Ghostwire

CVE-2026-5306: The Check & Log Email WordPress plugin before 2.0.13 does not properly handle email replacement, which could allow...

MEDIUM CVSS 0.0

Published: April 28, 2026 | Last Modified: April 28, 2026

Description

The Check & Log Email WordPress plugin before 2.0.13 does not properly handle email replacement, which could allow unauthenticated users to perform Stored XSS attacks when the email encoder setting is enabled

Ghostwire Analysis — What This Means Practically

This analysis is generated by Ghostwire from NVD, CISA KEV, EPSS, and open-source intelligence data. Verify findings through primary sources before acting.

Security Coverage (1 articles)

References