plugin

Emailkit Vulnerabilities

6 known security issues reported for the Emailkit WordPress plugin. Most recent disclosed May 4, 2026.

6 medium

Running Emailkit on your site? Check whether your installed version is affected.

Scan your site free

EmailKit <= 1.6.5 - Authenticated (Author+) Arbitrary File Read via 'emailkit-editor-template' REST Parameter

medium

The EmailKit plugin for WordPress is vulnerable to Arbitrary File Read in all versions up to and including 1.6.5. This is due to a flawed path traversal validation in the create_template() method of the CheckForm class, where realpath() is called on the allowed base directory (wp-content/uploads/emailkit/templates/) wh...

CVSS:
6.5
Affected:
up to 1.6.5
Fixed in:
1.6.6
Disclosed:
May 4, 2026

CVE-2026-5957 on NVD →

EmailKit - Authenticated (Administrator+) Path Traversal via 'emailkit-editor-template' REST API Parameter vulnerability

medium

Authenticated (Administrator+) Path Traversal via 'emailkit-editor-template' REST API Parameter vulnerability

CVSS:
4.9
Affected:
up to 1.6.3
Fixed in:
1.6.4
Disclosed:
Mar 20, 2026

EmailKit <= 1.6.3 - Authenticated (Administrator+) Path Traversal via 'emailkit-editor-template' REST API Parameter

medium

The EmailKit – Email Customizer for WooCommerce & WP plugin for WordPress is vulnerable to arbitrary file read via path traversal in all versions up to, and including, 1.6.3. This is due to the action() function in the TemplateData class passing user-supplied input from the 'emailkit-editor-template' REST API parameter...

CVSS:
4.9
Affected:
up to 1.6.3
Fixed in:
1.6.4
Disclosed:
Mar 20, 2026

CVE-2026-3474 on NVD →

EmailKit – Email Customizer for WooCommerce & WP <= 1.6.2 - Missing Authorization to Authenticated (Subscriber+) Arbitrary Post Title Modification

medium

The EmailKit – Email Customizer for WooCommerce & WP plugin for WordPress is vulnerable to unauthorized data modification due to a missing capability check on the 'update_template_data' function in all versions up to, and including, 1.6.2. This makes it possible for authenticated attackers, with Subscriber-level access...

CVSS:
4.3
Affected:
up to 1.6.2
Fixed in:
1.6.3
Disclosed:
Feb 17, 2026

CVE-2026-1925 on NVD →

EmailKit <= 1.6.1 - Authenticated (Author+) Arbitrary File Read via Path Traversal

medium

The EmailKit plugin for WordPress is vulnerable to Arbitrary File Read via Path Traversal in all versions up to, and including, 1.6.1. This is due to missing path validation in the create_template REST API endpoint where user-controlled input from the emailkit-editor-template parameter is passed directly to file_get_co...

CVSS:
6.5
Affected:
up to 1.6.1
Fixed in:
1.6.2
Disclosed:
Jan 6, 2026

CVE-2025-14059 on NVD →

EmailKit <= 1.6.0 - Missing Authorization to Authenticated (Author+) Arbitrary Content Deletion

medium

The EmailKit – Email Customizer for WooCommerce & WP plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in all versions up to, and including, 1.6.0. This makes it possible for authenticated attackers, with Author-level access and above, to delete arbitrary content.

CVSS:
4.3
Affected:
up to 1.6.0
Fixed in:
1.6.1
Disclosed:
Sep 26, 2025

CVE-2025-60106 on NVD →

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database