Email Log <= 2.4.8 - Unauthenticated Hook Injection
high
The Email Log plugin for WordPress is vulnerable to Unauthenticated Hook Injection in all versions up to, and including, 2.4.8 via the check_nonce function. This makes it possible for unauthenticated attackers to execute actions with hooks in WordPress under certain circumstances. The action the attacker wishes to exec...
- CVSS:
- 8.1
- Affected:
- up to 2.4.8
- Fixed in:
- 2.4.9
- Disclosed:
- May 23, 2024
CVE-2024-0867 on NVD →
Email Log <= 2.4.7 - Reflected Cross-Site Scripting
medium
The Email Log WordPress plugin before 2.4.8 does not escape the d parameter before outputting it back in an attribute in the Log page, leading to a Reflected Cross-Site Scripting issue
- CVSS:
- 6.1
- Affected:
- up to 2.4.7
- Fixed in:
- 2.4.8
- Disclosed:
- Nov 8, 2021
CVE-2021-24924 on NVD →
Email Log <= 2.4.6 - Admin+ SQL Injection
high
The Email Log WordPress plugin before 2.4.7 does not properly validate, sanitise and escape the "orderby" and "order" GET parameters before using them in SQL statement in the admin dashboard, leading to SQL injections
- CVSS:
- 7.2
- Affected:
- up to 2.4.6
- Fixed in:
- 2.4.7
- Disclosed:
- Oct 18, 2021
CVE-2021-24758 on NVD →
Email Log <= 2.2.2 - Stored Cross-Site Scripting
medium
The Email Log plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the '$log_item' variable in versions up to, and including, 2.2.2 due to insufficient input sanitization and output escaping. This makes it possible for authorized attackers to inject arbitrary web scripts in pages that will execute when...
- CVSS:
- 6.4
- Affected:
- up to 2.2.2
- Fixed in:
- 2.2.3
- Disclosed:
- Nov 11, 2017
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database