๐Ÿ” CVE Alert

CVE-2025-24567

MEDIUM 6.5

WordPress WP Mailster plugin <= 1.8.16.0 - Sensitive Data Exposure vulnerability

CVSS Score
6.5
EPSS Score
0.2%
EPSS Percentile
43th

Insertion of Sensitive Information Into Sent Data vulnerability in brandtoss WP Mailster wp-mailster allows Retrieve Embedded Sensitive Data.This issue affects WP Mailster: from n/a through <= 1.8.16.0.

CWE CWE-201
Vendor brandtoss
Product wp mailster
Published Feb 14, 2025
Last Updated May 11, 2026
Stay Ahead of the Next One

Get instant alerts for brandtoss wp mailster

Be the first to know when new medium vulnerabilities affecting brandtoss wp mailster are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Attack Vector
Network
Attack Complexity
Low
Privileges Required
Low
User Interaction
None
Scope
Unchanged
Confidentiality
High
Integrity
None
Availability
None

Affected Versions

brandtoss / WP Mailster
0 โ‰ค 1.8.16.0

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
patchstack.com: https://patchstack.com/database/Wordpress/Plugin/wp-mailster/vulnerability/wordpress-wp-mailster-plugin-1-8-16-0-sensitive-data-exposure-vulnerability-2?_s_id=cve

Credits

Mika | Patchstack Bug Bounty Program