๐Ÿ” CVE Alert

CVE-2026-1661

MEDIUM 4.3

WP Mail Logging < 1.17.0 - Unauthenticated HTML Injection

CVSS Score
4.3
EPSS Score
0.0%
EPSS Percentile
0th

The WP Mail Logging WordPress plugin before 1.17.0 does not properly restrict the HTML and CSS of logged emails before rendering them in its admin log screens, allowing unauthenticated users to inject styled content and links, for example through a public contact form, that can deceive an administrator viewing the log and send their browser to an attacker-controlled page.

Vendor unknown
Product wp mail logging
Published Oct 2, 2026
Stay Ahead of the Next One

Get instant alerts for unknown wp mail logging

Be the first to know when new medium vulnerabilities affecting unknown wp mail logging are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality
Integrity
Availability

Affected Versions

Unknown / WP Mail Logging
0 < 1.17.0

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
wpscan.com: https://wpscan.com/vulnerability/dde19119-7ea8-4d02-bf89-7a6b0ca010b5/

Credits

Kasia Sok WPScan