WP Email Template <= 2.8.6 - Cross-Site Request Forgery
medium
The WP Email Template plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.8.6. This is due to missing or incorrect nonce validation on a function. This makes it possible for unauthenticated attackers to perform an unauthorized action granted they can trick a site adm...
- CVSS:
- 4.3
- Affected:
- up to 2.8.6
- Fixed in:
- 2.8.7
- Disclosed:
- Sep 5, 2025
CVE-2025-58800 on NVD →
WP Email Template [wp-email-template] <= 2.8.3 (unfixed)
unknown
[en] Cross-Site Request Forgery (CSRF) vulnerability in Steve Truman WP Email Template allows Cross Site Request Forgery. This issue affects WP Email Template: from n/a through 2.8.3.
- Affected:
- up to 2.8.3
- Fix:
- No patched version reported
- Disclosed:
- Sep 5, 2025
CVE-2025-58800 on NVD →
WP Email Template [wp-email-template] < 2.2.11 (closed)
unknown
[en] The WP HTML Mail plugin for WordPress is vulnerable to HTML injection in versions up to, and including, 2.2.10 due to insufficient input sanitization. This makes it possible for unauthenticated attackers to inject arbitrary HTML in pages that execute if they can successfully trick a administrator into performing a...
- Affected:
- up to 2.2.11
- Fixed in:
- 2.2.11
- Disclosed:
- Jun 7, 2023
CVE-2019-25144 on NVD →
a3 Lazy Load <= 2.6.0 - Cross-Site Request Forgery to Settings Reset
high
The following plugins for WordPress are vulnerable to Cross-Site Request Forgery:
a3 Lazy Load (<= 2.6.0), Contact Us Page – Contact People (<= 3.6.1), a3 Portfolio (<= 3.0.1), Dynamic Product Gallery for WooCommerce (3.0.1), a3 Responsive Slider (<= 2.2.0), Compare Products for WooCommerce (<= 2.8.2), Products Quic...
- CVSS:
- 8.8
- Affected:
- up to 2.6.2
- Fixed in:
- 2.6.3
- Disclosed:
- Nov 2, 2022
WP Email Template [wp-email-template] < 2.6.3 (closed)
unknown
The following plugins for WordPress are vulnerable to Cross-Site Request Forgery:
a3 Lazy Load (<= 2.6.0), Contact Us Page – Contact People (<= 3.6.1), a3 Portfolio (<= 3.0.1), Dynamic Product Gallery for WooCommerce (3.0.1), a3 Responsive Slider (<= 2.2.0), Compare Products for WooCommerce (<= 2.8.2), Products Quic...
- Affected:
- up to 2.6.3
- Fixed in:
- 2.6.3
- Disclosed:
- Nov 2, 2022
WP HTML Mail < 2.2.11 - HTML injection
medium
The WP HTML Mail plugin for WordPress is vulnerable to HTML injection in versions up to, and including, 2.2.10 due to insufficient input sanitization. This makes it possible for unauthenticated attackers to inject arbitrary HTML in pages that execute if they can successfully trick a administrator into performing an act...
- CVSS:
- 5.4
- Affected:
- up to 2.2.11
- Fixed in:
- 2.2.11
- Disclosed:
- Oct 25, 2019
CVE-2019-25144 on NVD →
WP Email Template [wp-email-template] < 2.2.11 (closed)
unknown
The WP HTML Mail plugin for WordPress is vulnerable to HTML injection in versions up to, and including, 2.2.10 due to insufficient input sanitization. This makes it possible for unauthenticated attackers to inject arbitrary HTML in pages that execute if they can successfully trick a administrator into performing an act...
- Affected:
- up to 2.2.11
- Fixed in:
- 2.2.11
- Disclosed:
- Oct 25, 2019
WP Email Template [wp-email-template] < 2.2.11 (closed)
unknown
The WP Email Template WordPress plugin was affected by a HTML Injection security vulnerability.
- Affected:
- up to 2.2.11
- Fixed in:
- 2.2.11
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database