Description
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in add-ons.org Email Templates Customizer for WordPress – Drag And Drop Email Templates Builder – YeeMail yeemail allows Stored XSS.This issue affects Email Templates Customizer for WordPress – Drag And Drop Email Templates Builder – YeeMail: from n/a through <= 2.1.4.
Published: 2025-01-09
Score: 6.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability is an improper neutralization of input during web page generation, enabling a stored cross‑site scripting (XSS) flaw in the YeeMail Email Templates Customizer plugin. An attacker can inject malicious JavaScript into an email template that is later rendered by the website. When an authenticated or unathenticated visitor views the template, the injected script runs in the victim’s browser, potentially allowing session hijacking, defacement, or the execution of arbitrary actions on behalf of the user.

Affected Systems

The issue affects the WordPress plugin named Email Templates Customizer for WordPress – Drag And Drop Email Templates Builder – YeeMail, available from add-ons.org. All released versions up to and including 2.1.4 contain the flaw. No specific downstream product versions are listed.

Risk and Exploitability

The CVSS score of 6.5 indicates a moderate severity vulnerability, and the EPSS score of less than 1% suggests a low current exploitation likelihood. The flaw is not listed in the CISA KEV catalog. The likely attack vector is an authenticated user who can edit or create email templates within the WordPress admin interface; the attacker would embed malicious content into a template that is subsequently served to other site visitors. Exploitation requires an authenticated session with template editing rights but does not grant direct control over the server or execute arbitrary code on the host.

Generated by OpenCVE AI on May 1, 2026 at 21:55 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade the YeeMail plugin to the latest released version that fixes the stored XSS issue.
  • If an immediate upgrade is not possible, limit the use of the plugin by disabling or removing all custom email templates until a patch is applied.
  • Restrict template editing privileges to trusted administrators and review user roles to ensure that only authorized personnel can modify email content.

Generated by OpenCVE AI on May 1, 2026 at 21:55 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2025-3006 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in add-ons.org Email Templates Customizer for WordPress – Drag And Drop Email Templates Builder – YeeMail allows Stored XSS.This issue affects Email Templates Customizer for WordPress – Drag And Drop Email Templates Builder – YeeMail: from n/a through 2.1.4.
History

Thu, 23 Apr 2026 15:00:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L'}


Wed, 01 Apr 2026 23:45:00 +0000

Type Values Removed Values Added
Description Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in add-ons.org Email Templates Customizer for WordPress – Drag And Drop Email Templates Builder – YeeMail allows Stored XSS.This issue affects Email Templates Customizer for WordPress – Drag And Drop Email Templates Builder – YeeMail: from n/a through 2.1.4. Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in add-ons.org Email Templates Customizer for WordPress – Drag And Drop Email Templates Builder – YeeMail yeemail allows Stored XSS.This issue affects Email Templates Customizer for WordPress – Drag And Drop Email Templates Builder – YeeMail: from n/a through <= 2.1.4.
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L'}


Fri, 10 Jan 2025 21:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 09 Jan 2025 15:45:00 +0000

Type Values Removed Values Added
Description Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in add-ons.org Email Templates Customizer for WordPress – Drag And Drop Email Templates Builder – YeeMail allows Stored XSS.This issue affects Email Templates Customizer for WordPress – Drag And Drop Email Templates Builder – YeeMail: from n/a through 2.1.4.
Title WordPress Email Templates Customizer YeeMail plugin <= 2.1.4 - Cross Site Scripting (XSS) vulnerability
Weaknesses CWE-79
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-04-28T16:11:07.549Z

Reserved: 2025-01-07T21:05:34.184Z

Link: CVE-2025-22802

cve-icon Vulnrichment

Updated: 2025-01-10T20:18:30.421Z

cve-icon NVD

Status : Deferred

Published: 2025-01-09T16:16:29.470

Modified: 2026-06-17T08:50:11.417

Link: CVE-2025-22802

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-05-01T22:00:14Z

Weaknesses
  • CWE-79

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')