<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:webfeeds="http://webfeeds.org/rss/1.0"><channel><title>Cpe:2.3:a:wordpress:mail_logging_wp_mail_catcher:*:*:*:*:*:*:*:* - CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/cpes/cpe2.3awordpressmail_logging_wp_mail_catcher/</link><description>Trending threats, MITRE ATT&amp;CK coverage, and detection metadata. Fed continuously.</description><generator>Hugo</generator><language>en</language><managingEditor>hello@craftedsignal.io</managingEditor><webMaster>hello@craftedsignal.io</webMaster><lastBuildDate>Sat, 03 Oct 2026 08:54:34 +0000</lastBuildDate><atom:link href="https://feed.craftedsignal.io/cpes/cpe2.3awordpressmail_logging_wp_mail_catcher/feed.xml" rel="self" type="application/rss+xml"/><image><url>https://feed.craftedsignal.io/favicon-32x32.png</url><title>CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/</link><width>32</width><height>32</height></image><webfeeds:icon>https://feed.craftedsignal.io/favicon.svg</webfeeds:icon><item><title>Stored XSS in WP Mail Catcher WordPress Plugin</title><link>https://feed.craftedsignal.io/briefs/2026-10-wp-mail-catcher-xss/</link><pubDate>Sat, 03 Oct 2026 08:54:34 +0000</pubDate><author>hello@craftedsignal.io</author><guid isPermaLink="true">https://feed.craftedsignal.io/briefs/2026-10-wp-mail-catcher-xss/</guid><description>The WP Mail Catcher plugin for WordPress is vulnerable to stored cross-site scripting (XSS) via inadequate sanitization of PHPMailer error messages, allowing unauthenticated attackers to execute arbitrary scripts in the context of administrative sessions.</description><content:encoded><![CDATA[<p>The Mail logging - WP Mail Catcher plugin for WordPress, in versions up to and including 2.1.12, contains a stored cross-site scripting (XSS) vulnerability. The issue stems from insufficient input sanitization and output escaping within the 'wp_mail_failed' hook, which handles PHPMailer error messages.</p>
<p>Attackers can leverage this vulnerability by injecting malicious scripts into mail fields via other plugins, such as Contact Form 7, that pass unauthenticated, user-controlled input to the WordPress mail system. When PHPMailer fails to send an email, it includes the malicious payload within the error message, which is subsequently logged by the WP Mail Catcher plugin. When an administrator or authorized user views the mail logs within the WordPress dashboard, the injected script executes in their browser. This allows for session hijacking, administrative action manipulation, or further credential theft within the WordPress environment.</p>
<h2 id="impact">Impact</h2>
<p>Successful exploitation allows unauthenticated attackers to execute arbitrary JavaScript in the browser of any user who views the mail logs. In typical WordPress deployments, this targets administrative users, potentially leading to full site compromise, unauthorized configuration changes, or the installation of malicious plugins.</p>
<h2 id="recommendation">Recommendation</h2>
<p>Update the WP Mail Catcher plugin to a version released after 2.1.12 that includes proper sanitization of the 'wp_mail_failed' error output. If an update is not immediately available, disable the plugin or restrict access to the mail logs page to only highly trusted administrative users.</p>
]]></content:encoded><category domain="severity">high</category><category domain="type">advisory</category><category>web-vulnerability</category><category>wordpress</category><category>xss</category></item></channel></rss>