plugin

Email Log Vulnerabilities

4 known security issues reported for the Email Log WordPress plugin. Most recent disclosed May 23, 2024.

2 high 2 medium

Running Email Log on your site? Check whether your installed version is affected.

Scan your site free

Email Log <= 2.4.8 - Unauthenticated Hook Injection

high

The Email Log plugin for WordPress is vulnerable to Unauthenticated Hook Injection in all versions up to, and including, 2.4.8 via the check_nonce function. This makes it possible for unauthenticated attackers to execute actions with hooks in WordPress under certain circumstances. The action the attacker wishes to exec...

CVSS:
8.1
Affected:
up to 2.4.8
Fixed in:
2.4.9
Disclosed:
May 23, 2024

CVE-2024-0867 on NVD →

Email Log <= 2.4.7 - Reflected Cross-Site Scripting

medium

The Email Log WordPress plugin before 2.4.8 does not escape the d parameter before outputting it back in an attribute in the Log page, leading to a Reflected Cross-Site Scripting issue

CVSS:
6.1
Affected:
up to 2.4.7
Fixed in:
2.4.8
Disclosed:
Nov 8, 2021

CVE-2021-24924 on NVD →

Email Log <= 2.4.6 - Admin+ SQL Injection

high

The Email Log WordPress plugin before 2.4.7 does not properly validate, sanitise and escape the "orderby" and "order" GET parameters before using them in SQL statement in the admin dashboard, leading to SQL injections

CVSS:
7.2
Affected:
up to 2.4.6
Fixed in:
2.4.7
Disclosed:
Oct 18, 2021

CVE-2021-24758 on NVD →

Email Log <= 2.2.2 - Stored Cross-Site Scripting

medium

The Email Log plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the '$log_item' variable in versions up to, and including, 2.2.2 due to insufficient input sanitization and output escaping. This makes it possible for authorized attackers to inject arbitrary web scripts in pages that will execute when...

CVSS:
6.4
Affected:
up to 2.2.2
Fixed in:
2.2.3
Disclosed:
Nov 11, 2017

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database