plugin

Wp Email Capture Vulnerabilities

13 known security issues reported for the Wp Email Capture WordPress plugin. Most recent disclosed Dec 31, 2025.

1 high 5 medium

Running Wp Email Capture on your site? Check whether your installed version is affected.

Scan your site free

Email Capture <= 3.12.5 - Cross-Site Request Forgery

medium

The Email Marketing Plugin – WP Email Capture plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 3.12.5. This is due to missing or incorrect nonce validation on a function. This makes it possible for unauthenticated attackers to perform an unauthorized action granted...

CVSS:
4.3
Affected:
up to 3.12.5
Fixed in:
3.12.6
Disclosed:
Dec 31, 2025

CVE-2025-68529 on NVD →

Email Marketing Plugin &#8211; WP Email Capture [wp-email-capture] <= 3.12.5 (unfixed)

unknown

[en] Cross-Site Request Forgery (CSRF) vulnerability in Rhys Wynne WP Email Capture wp-email-capture allows Cross Site Request Forgery.This issue affects WP Email Capture: from n/a through <= 3.12.5.

Affected:
up to 3.12.5
Fix:
No patched version reported
Disclosed:
Dec 24, 2025

CVE-2025-68529 on NVD →

Email Marketing Plugin &#8211; WP Email Capture [wp-email-capture] <= 3.12.4 (unfixed)

unknown

[en] Missing Authorization vulnerability in Rhys Wynne WP Email Capture wp-email-capture allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WP Email Capture: from n/a through <= 3.12.4.

Affected:
up to 3.12.4
Fix:
No patched version reported
Disclosed:
Dec 9, 2025

CVE-2025-67578 on NVD →

Email Capture <= 3.12.4 - Missing Authorization

medium

The Email Marketing Plugin – WP Email Capture plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in all versions up to, and including, 3.12.4. This makes it possible for authenticated attackers, with Subscriber-level access and above, to perform an unauthorized act...

CVSS:
4.3
Affected:
up to 3.12.4
Fixed in:
3.12.5
Disclosed:
Dec 8, 2025

CVE-2025-67578 on NVD →

Email Marketing Plugin &#8211; WP Email Capture [wp-email-capture] < 3.11

unknown

[en] Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Winwar Media WordPress Email Marketing Plugin – WP Email Capture.This issue affects WordPress Email Marketing Plugin – WP Email Capture: from n/a through 3.10.

Affected:
up to 3.11
Fixed in:
3.11
Disclosed:
Dec 21, 2023

CVE-2023-28421 on NVD →

Email Marketing Plugin &#8211; WP Email Capture [wp-email-capture] < 3.10

unknown

[en] Cross-Site Request Forgery (CSRF) vulnerability in Winwar Media WP Email Capture plugin <= 3.9.3 versions.

Affected:
up to 3.10
Fixed in:
3.10
Disclosed:
May 23, 2023

CVE-2023-23724 on NVD →

Email Marketing Plugin &#8211; WP Email Capture [wp-email-capture] < 3.11

unknown

[en] Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Winwar Media WP Email Capture plugin <= 3.9.3 versions.

Affected:
up to 3.11
Fixed in:
3.11
Disclosed:
May 2, 2023

CVE-2023-23723 on NVD →

WordPress Email Marketing Plugin – WP Email Capture <= 3.10 - Information Exposure via wp_email_capture_options_process

medium

The WordPress Email Marketing Plugin – WP Email Capture plugin for WordPress is vulnerable to Sensitive Information Exposure in versions up to, and including, 3.10 via the wp_email_capture_options_process function hooked via admin_init. This makes it possible for unauthenticated attackers to extract sensitive data incl...

CVSS:
5.3
Affected:
up to 3.10
Fixed in:
3.11
Disclosed:
Mar 15, 2023

CVE-2023-28421 on NVD →

WordPress Email Marketing Plugin – WP Email Capture <= 3.10 - Missing Authorization to Email Capture List Download

high

The WP Email Capture plugin for WordPress is vulnerable to unauthorized Email Capture list download due to a missing capability check on the wp_email_capture_options_process function in versions up to, and including, 3.10. This makes it possible for unauthenticated attackers to download email captures.

CVSS:
8.2
Affected:
up to 3.10
Fixed in:
3.11
Disclosed:
Mar 14, 2023

CVE-2023-28421 on NVD →

Email Marketing Plugin &#8211; WP Email Capture [wp-email-capture] < 3.11

unknown

The WP Email Capture plugin for WordPress is vulnerable to unauthorized Email Capture list download due to a missing capability check on the wp_email_capture_options_process function in versions up to, and including, 3.10. This makes it possible for unauthenticated attackers to download email captures.

Affected:
up to 3.11
Fixed in:
3.11
Disclosed:
Mar 14, 2023

WordPress Email Marketing Plugin – WP Email Capture <= 3.9.3 - Cross Site Request Forgery

medium

The WordPress Email Marketing Plugin – WP Email Capture plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 3.9.3. This is due to missing nonce validation in the wp_email_capture_options_process() function. This makes it possible for unauthenticated attackers to modify ema...

CVSS:
4.3
Affected:
up to 3.9.3
Fixed in:
3.10
Disclosed:
Feb 15, 2023

CVE-2023-23724 on NVD →

WP Email Capture <= 3.9.3 - Authenticated (Administrator+) Stored Cross-Site Scripting

medium

The WP Email Capture plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in versions up to, and including, 3.9.3 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrative-level permissions and above, to inject arb...

CVSS:
4.4
Affected:
up to 3.9.3
Fixed in:
3.10
Disclosed:
Jan 30, 2023

CVE-2023-23723 on NVD →

Email Marketing Plugin &#8211; WP Email Capture [wp-email-capture] < 3.10

unknown

The WP Email Capture plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in versions up to, and including, 3.9.3 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrative-level permissions and above, to inject arb...

Affected:
up to 3.10
Fixed in:
3.10
Disclosed:
Jan 30, 2023

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database