EmailKit <= 1.6.5 - Authenticated (Author+) Arbitrary File Read via 'emailkit-editor-template' REST Parameter
medium
The EmailKit plugin for WordPress is vulnerable to Arbitrary File Read in all versions up to and including 1.6.5. This is due to a flawed path traversal validation in the create_template() method of the CheckForm class, where realpath() is called on the allowed base directory (wp-content/uploads/emailkit/templates/) wh...
- CVSS:
- 6.5
- Affected:
- up to 1.6.5
- Fixed in:
- 1.6.6
- Disclosed:
- May 4, 2026
CVE-2026-5957 on NVD →
EmailKit - Authenticated (Administrator+) Path Traversal via 'emailkit-editor-template' REST API Parameter vulnerability
medium
Authenticated (Administrator+) Path Traversal via 'emailkit-editor-template' REST API Parameter vulnerability
- CVSS:
- 4.9
- Affected:
- up to 1.6.3
- Fixed in:
- 1.6.4
- Disclosed:
- Mar 20, 2026
EmailKit <= 1.6.3 - Authenticated (Administrator+) Path Traversal via 'emailkit-editor-template' REST API Parameter
medium
The EmailKit – Email Customizer for WooCommerce & WP plugin for WordPress is vulnerable to arbitrary file read via path traversal in all versions up to, and including, 1.6.3. This is due to the action() function in the TemplateData class passing user-supplied input from the 'emailkit-editor-template' REST API parameter...
- CVSS:
- 4.9
- Affected:
- up to 1.6.3
- Fixed in:
- 1.6.4
- Disclosed:
- Mar 20, 2026
CVE-2026-3474 on NVD →
EmailKit – Email Customizer for WooCommerce & WP <= 1.6.2 - Missing Authorization to Authenticated (Subscriber+) Arbitrary Post Title Modification
medium
The EmailKit – Email Customizer for WooCommerce & WP plugin for WordPress is vulnerable to unauthorized data modification due to a missing capability check on the 'update_template_data' function in all versions up to, and including, 1.6.2. This makes it possible for authenticated attackers, with Subscriber-level access...
- CVSS:
- 4.3
- Affected:
- up to 1.6.2
- Fixed in:
- 1.6.3
- Disclosed:
- Feb 17, 2026
CVE-2026-1925 on NVD →
EmailKit <= 1.6.1 - Authenticated (Author+) Arbitrary File Read via Path Traversal
medium
The EmailKit plugin for WordPress is vulnerable to Arbitrary File Read via Path Traversal in all versions up to, and including, 1.6.1. This is due to missing path validation in the create_template REST API endpoint where user-controlled input from the emailkit-editor-template parameter is passed directly to file_get_co...
- CVSS:
- 6.5
- Affected:
- up to 1.6.1
- Fixed in:
- 1.6.2
- Disclosed:
- Jan 6, 2026
CVE-2025-14059 on NVD →
EmailKit <= 1.6.0 - Missing Authorization to Authenticated (Author+) Arbitrary Content Deletion
medium
The EmailKit – Email Customizer for WooCommerce & WP plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in all versions up to, and including, 1.6.0. This makes it possible for authenticated attackers, with Author-level access and above, to delete arbitrary content.
- CVSS:
- 4.3
- Affected:
- up to 1.6.0
- Fixed in:
- 1.6.1
- Disclosed:
- Sep 26, 2025
CVE-2025-60106 on NVD →
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database