{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/products/mail-logging--wp-mail-catcher--2.1.12/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:wordpress:mail_logging_wp_mail_catcher:*:*:*:*:*:*:*:*"],"_cs_cves":[{"cvss":7.2,"id":"CVE-2026-93889"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["Mail logging – WP Mail Catcher (\u003c= 2.1.12)"],"_cs_severities":["high"],"_cs_tags":["web-vulnerability","wordpress","xss"],"_cs_type":"advisory","_cs_vendors":["WordPress"],"content_html":"\u003cp\u003eThe Mail logging - WP Mail Catcher plugin for WordPress, in versions up to and including 2.1.12, contains a stored cross-site scripting (XSS) vulnerability. The issue stems from insufficient input sanitization and output escaping within the 'wp_mail_failed' hook, which handles PHPMailer error messages.\u003c/p\u003e\n\u003cp\u003eAttackers can leverage this vulnerability by injecting malicious scripts into mail fields via other plugins, such as Contact Form 7, that pass unauthenticated, user-controlled input to the WordPress mail system. When PHPMailer fails to send an email, it includes the malicious payload within the error message, which is subsequently logged by the WP Mail Catcher plugin. When an administrator or authorized user views the mail logs within the WordPress dashboard, the injected script executes in their browser. This allows for session hijacking, administrative action manipulation, or further credential theft within the WordPress environment.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation allows unauthenticated attackers to execute arbitrary JavaScript in the browser of any user who views the mail logs. In typical WordPress deployments, this targets administrative users, potentially leading to full site compromise, unauthorized configuration changes, or the installation of malicious plugins.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cp\u003eUpdate the WP Mail Catcher plugin to a version released after 2.1.12 that includes proper sanitization of the 'wp_mail_failed' error output. If an update is not immediately available, disable the plugin or restrict access to the mail logs page to only highly trusted administrative users.\u003c/p\u003e\n","date_modified":"2026-10-03T08:54:34Z","date_published":"2026-10-03T08:54:34Z","id":"https://feed.craftedsignal.io/briefs/2026-10-wp-mail-catcher-xss/","summary":"The WP Mail Catcher plugin for WordPress is vulnerable to stored cross-site scripting (XSS) via inadequate sanitization of PHPMailer error messages, allowing unauthenticated attackers to execute arbitrary scripts in the context of administrative sessions.","title":"Stored XSS in WP Mail Catcher WordPress Plugin","url":"https://feed.craftedsignal.io/briefs/2026-10-wp-mail-catcher-xss/"}],"language":"en","title":"CraftedSignal Threat Feed - Mail Logging – WP Mail Catcher (\u003c= 2.1.12)","version":"https://jsonfeed.org/version/1.1"}