plugin

Emails Catch All Vulnerabilities

1 known security issue reported for the Emails Catch All WordPress plugin. Most recent disclosed Oct 11, 2025.

1 high

Running Emails Catch All on your site? Check whether your installed version is affected.

Scan your site free

Emails Catch <= 3.5.3 - Authenticated (Subscriber+) Information Exposure to Password Reset and Privilege Escalation

high

The Emails Catch All plugin for WordPress is vulnerable to privilege escalation via email log exposure in all versions up to, and including, 3.5.3. This is due to the plugin not properly restricting access to email logs. This makes it possible for authenticated attackers, with Subscriber-level access and above, to trig...

CVSS:
8.8
Affected:
up to 3.5.3
Fixed in:
3.5.4
Disclosed:
Oct 11, 2025

CVE-2025-60041 on NVD →

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database