CVE-2026-1661
WP Mail Logging < 1.17.0 - Unauthenticated HTML Injection
CVSS Score
4.3
EPSS Score
0.0%
EPSS Percentile
0th
The WP Mail Logging WordPress plugin before 1.17.0 does not properly restrict the HTML and CSS of logged emails before rendering them in its admin log screens, allowing unauthenticated users to inject styled content and links, for example through a public contact form, that can deceive an administrator viewing the log and send their browser to an attacker-controlled page.
| Vendor | unknown |
| Product | wp mail logging |
| Published | Oct 2, 2026 |
Stay Ahead of the Next One
Get instant alerts for unknown wp mail logging
Be the first to know when new medium vulnerabilities affecting unknown wp mail logging are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
CVSS v3 Breakdown
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality
Integrity
Availability
Affected Versions
Unknown / WP Mail Logging
0 < 1.17.0
References
Credits
Kasia Sok WPScan