plugin

Wp Email Template Vulnerabilities

8 known security issues reported for the Wp Email Template WordPress plugin. Most recent disclosed Sep 5, 2025.

1 high 2 medium

Running Wp Email Template on your site? Check whether your installed version is affected.

Scan your site free

WP Email Template <= 2.8.6 - Cross-Site Request Forgery

medium

The WP Email Template plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.8.6. This is due to missing or incorrect nonce validation on a function. This makes it possible for unauthenticated attackers to perform an unauthorized action granted they can trick a site adm...

CVSS:
4.3
Affected:
up to 2.8.6
Fixed in:
2.8.7
Disclosed:
Sep 5, 2025

CVE-2025-58800 on NVD →

WP Email Template [wp-email-template] <= 2.8.3 (unfixed)

unknown

[en] Cross-Site Request Forgery (CSRF) vulnerability in Steve Truman WP Email Template allows Cross Site Request Forgery. This issue affects WP Email Template: from n/a through 2.8.3.

Affected:
up to 2.8.3
Fix:
No patched version reported
Disclosed:
Sep 5, 2025

CVE-2025-58800 on NVD →

WP Email Template [wp-email-template] < 2.2.11 (closed)

unknown

[en] The WP HTML Mail plugin for WordPress is vulnerable to HTML injection in versions up to, and including, 2.2.10 due to insufficient input sanitization. This makes it possible for unauthenticated attackers to inject arbitrary HTML in pages that execute if they can successfully trick a administrator into performing a...

Affected:
up to 2.2.11
Fixed in:
2.2.11
Disclosed:
Jun 7, 2023

CVE-2019-25144 on NVD →

a3 Lazy Load <= 2.6.0 - Cross-Site Request Forgery to Settings Reset

high

The following plugins for WordPress are vulnerable to Cross-Site Request Forgery: a3 Lazy Load (<= 2.6.0), Contact Us Page – Contact People (<= 3.6.1), a3 Portfolio (<= 3.0.1), Dynamic Product Gallery for WooCommerce (3.0.1), a3 Responsive Slider (<= 2.2.0), Compare Products for WooCommerce (<= 2.8.2), Products Quic...

CVSS:
8.8
Affected:
up to 2.6.2
Fixed in:
2.6.3
Disclosed:
Nov 2, 2022

WP Email Template [wp-email-template] < 2.6.3 (closed)

unknown

The following plugins for WordPress are vulnerable to Cross-Site Request Forgery: a3 Lazy Load (<= 2.6.0), Contact Us Page – Contact People (<= 3.6.1), a3 Portfolio (<= 3.0.1), Dynamic Product Gallery for WooCommerce (3.0.1), a3 Responsive Slider (<= 2.2.0), Compare Products for WooCommerce (<= 2.8.2), Products Quic...

Affected:
up to 2.6.3
Fixed in:
2.6.3
Disclosed:
Nov 2, 2022

WP HTML Mail < 2.2.11 - HTML injection

medium

The WP HTML Mail plugin for WordPress is vulnerable to HTML injection in versions up to, and including, 2.2.10 due to insufficient input sanitization. This makes it possible for unauthenticated attackers to inject arbitrary HTML in pages that execute if they can successfully trick a administrator into performing an act...

CVSS:
5.4
Affected:
up to 2.2.11
Fixed in:
2.2.11
Disclosed:
Oct 25, 2019

CVE-2019-25144 on NVD →

WP Email Template [wp-email-template] < 2.2.11 (closed)

unknown

The WP HTML Mail plugin for WordPress is vulnerable to HTML injection in versions up to, and including, 2.2.10 due to insufficient input sanitization. This makes it possible for unauthenticated attackers to inject arbitrary HTML in pages that execute if they can successfully trick a administrator into performing an act...

Affected:
up to 2.2.11
Fixed in:
2.2.11
Disclosed:
Oct 25, 2019

WP Email Template [wp-email-template] < 2.2.11 (closed)

unknown

The WP Email Template WordPress plugin was affected by a HTML Injection security vulnerability.

Affected:
up to 2.2.11
Fixed in:
2.2.11

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database