CVE-2026-5306
Check & Log Email < 2.0.13 - Unauthenticated Stored XSS
CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th
The Check & Log Email WordPress plugin before 2.0.13 does not properly handle email replacement, which could allow unauthenticated users to perform Stored XSS attacks when the email encoder setting is enabled
| Vendor | unknown |
| Product | check & log email |
| Published | Apr 28, 2026 |
Stay Ahead of the Next One
Get instant alerts for unknown check & log email
Be the first to know when new unknown vulnerabilities affecting unknown check & log email are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
Affected Versions
Unknown / Check & Log Email
0 < 2.0.13
References
Credits
Matthew Rollings WPScan