Stored XSS in WP Mail Catcher WordPress Plugin
The WP Mail Catcher plugin for WordPress is vulnerable to stored cross-site scripting (XSS) via inadequate sanitization of PHPMailer error messages, allowing unauthenticated attackers to execute arbitrary scripts in the context of administrative sessions.
CVE search metadata
CVE search record: CVE-2026-93889. Severity: high. CVSS: 7.2. KEV: no. Product: Mail logging – WP Mail Catcher (<= 2.1.12). Brief: Stored XSS in WP Mail Catcher WordPress Plugin. Brief link: https://feed.craftedsignal.io/briefs/2026-10-wp-mail-catcher-xss/
The Mail logging - WP Mail Catcher plugin for WordPress, in versions up to and including 2.1.12, contains a stored cross-site scripting (XSS) vulnerability. The issue stems from insufficient input sanitization and output escaping within the 'wp_mail_failed' hook, which handles PHPMailer error messages.
Attackers can leverage this vulnerability by injecting malicious scripts into mail fields via other plugins, such as Contact Form 7, that pass unauthenticated, user-controlled input to the WordPress mail system. When PHPMailer fails to send an email, it includes the malicious payload within the error message, which is subsequently logged by the WP Mail Catcher plugin. When an administrator or authorized user views the mail logs within the WordPress dashboard, the injected script executes in their browser. This allows for session hijacking, administrative action manipulation, or further credential theft within the WordPress environment.
Impact
Successful exploitation allows unauthenticated attackers to execute arbitrary JavaScript in the browser of any user who views the mail logs. In typical WordPress deployments, this targets administrative users, potentially leading to full site compromise, unauthorized configuration changes, or the installation of malicious plugins.
Recommendation
Update the WP Mail Catcher plugin to a version released after 2.1.12 that includes proper sanitization of the 'wp_mail_failed' error output. If an update is not immediately available, disable the plugin or restrict access to the mail logs page to only highly trusted administrative users.
Immediate actions
Upgrade WP Mail Catcher to a version beyond 2.1.12
Mitigations
Disable WP Mail Catcher if update cannot be applied
CVE-2026-93889