Description
Cross-Site Request Forgery (CSRF) vulnerability in Soli WP Mail Options wp-mail-options allows Stored XSS.This issue affects WP Mail Options: from n/a through <= 0.2.3.
Published: 2025-06-06
Score: 7.1 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The WP Mail Options plugin contains a Cross‑Site Request Forgery flaw that permits an attacker to store malicious JavaScript in the site’s content. When an authenticated user follows a crafted link, the plugin accepts the payload without verification and preserves it for future page loads. Stored XSS allows the attacker to run arbitrary code in the victim’s browser, enabling cookie theft, session hijacking or defacement. The vulnerability aligns with CWE‑352 and carries a CVSS score of 7.1, indicating a high potential for exploitation once the condition is met.

Affected Systems

The flaw affects the Soli WordPress plugin WP Mail Options, version 0.2.3 and earlier. Users running any of these versions are at risk.

Risk and Exploitability

The vulnerability is scored moderate to high, but the EPSS is below 1 %, suggesting that widespread exploitation is presently unlikely. The attack requires an authenticated session and a crafted URL, so the typical vector is a CSRF attempt embedded in an email or external site. Once an attacker tricks a logged‑in user into visiting the link, the plugin will persist the XSS payload and the victim’s browser will execute it with the user’s privileges. The flaw is not listed in CISA’s KEV catalog, but the combination of CSRF and stored XSS remains a serious threat to site integrity and user credentials.

Generated by OpenCVE AI on May 1, 2026 at 07:47 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade WP Mail Options to version 0.2.4 or later to remove the CSRF flaw.
  • If upgrading immediately is not possible, disable the plugin until a patch is applied.
  • Consider implementing a Content‑Security‑Policy that blocks inline scripts to mitigate the impact of any stored XSS payload.

Generated by OpenCVE AI on May 1, 2026 at 07:47 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2025-17174 Cross-Site Request Forgery (CSRF) vulnerability in Soli WP Mail Options allows Stored XSS. This issue affects WP Mail Options: from n/a through 0.2.3.
History

Thu, 23 Apr 2026 15:00:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 7.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L'}


Wed, 01 Apr 2026 23:45:00 +0000

Type Values Removed Values Added
Description Cross-Site Request Forgery (CSRF) vulnerability in Soli WP Mail Options allows Stored XSS. This issue affects WP Mail Options: from n/a through 0.2.3. Cross-Site Request Forgery (CSRF) vulnerability in Soli WP Mail Options wp-mail-options allows Stored XSS.This issue affects WP Mail Options: from n/a through <= 0.2.3.
References
Metrics cvssV3_1

{'score': 7.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L'}


Fri, 06 Jun 2025 17:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 06 Jun 2025 13:15:00 +0000

Type Values Removed Values Added
Description Cross-Site Request Forgery (CSRF) vulnerability in Soli WP Mail Options allows Stored XSS. This issue affects WP Mail Options: from n/a through 0.2.3.
Title WordPress WP Mail Options plugin <= 0.2.3 - Cross Site Request Forgery (CSRF) to Stored XSS vulnerability
Weaknesses CWE-352
References
Metrics cvssV3_1

{'score': 7.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-04-28T16:11:52.189Z

Reserved: 2025-03-11T08:10:36.161Z

Link: CVE-2025-28981

cve-icon Vulnrichment

Updated: 2025-06-06T16:10:26.026Z

cve-icon NVD

Status : Deferred

Published: 2025-06-06T13:15:28.980

Modified: 2026-06-17T09:04:59.600

Link: CVE-2025-28981

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-05-01T08:00:13Z

Weaknesses
  • CWE-352

    Cross-Site Request Forgery (CSRF)