Emails Catch <= 3.5.3 - Authenticated (Subscriber+) Information Exposure to Password Reset and Privilege Escalation
highThe Emails Catch All plugin for WordPress is vulnerable to privilege escalation via email log exposure in all versions up to, and including, 3.5.3. This is due to the plugin not properly restricting access to email logs. This makes it possible for authenticated attackers, with Subscriber-level access and above, to trig...
- CVSS:
- 8.8
- Affected:
- up to 3.5.3
- Fixed in:
- 3.5.4
- Disclosed:
- Oct 11, 2025