Description
Authentication Bypass Using an Alternate Path or Channel vulnerability in Iulia Cazan Emails Catch All emails-catch-all allows Password Recovery Exploitation.This issue affects Emails Catch All: from n/a through <= 3.5.3.
Published: 2025-10-22
Score: 8.8 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The CVE describes an authentication bypass in the Emails Catch All plugin developed by Iulia Cazan that exploits the password‑recovery path. The flaw permits an unauthenticated user to trigger a password reset and then use the reset token to authenticate without knowing the original password. Based on the description, it is inferred that the attacker can obtain unrestricted administrative access to the WordPress site, enabling data theft, defacement, or further lateral movement.

Affected Systems

All installations of the Emails Catch All plugin by Iulia Cazan from its first release through version 3.5.3 are vulnerable. Site owners should verify the plugin version and ensure it is newer than 3.5.3 or otherwise mitigate the risk.

Risk and Exploitability

The CVSS score of 8.8 classifies this as a high‑severity flaw, while the EPSS score of less than 1% indicates a currently low likelihood of exploitation in the wild. The vulnerability is not listed in the CISA KEV catalog. The attack requires only access to the publicly exposed password‑reset form offered by the plugin, with no advanced techniques or additional privileges needed. Although widespread exploitation appears limited at present, the combination of a high CVSS rating and the absence of KEV status means that the risk remains significant for WordPress sites running the affected plugin.

Generated by OpenCVE AI on April 30, 2026 at 05:30 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade the Emails Catch All plugin to any release newer than version 3.5.3, which contains the fix for the authentication bypass.
  • If an upgrade is not possible immediately, uninstall or disable the plugin completely to eliminate the vulnerable authentication pathway.
  • After remediation, enforce strong, unique passwords for all administrative accounts and enable multi‑factor authentication where possible to reduce the impact of any potential credential compromise.

Generated by OpenCVE AI on April 30, 2026 at 05:30 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 27 Apr 2026 16:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Thu, 23 Apr 2026 15:00:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:C/C:H/I:L/A:L'}

cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}


Tue, 20 Jan 2026 15:30:00 +0000


Tue, 20 Jan 2026 14:45:00 +0000


Thu, 13 Nov 2025 11:30:00 +0000


Thu, 13 Nov 2025 10:45:00 +0000


Thu, 23 Oct 2025 14:15:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:C/C:H/I:L/A:L'}

ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 23 Oct 2025 10:30:00 +0000

Type Values Removed Values Added
First Time appeared Wordpress
Wordpress wordpress
Vendors & Products Wordpress
Wordpress wordpress

Wed, 22 Oct 2025 14:45:00 +0000

Type Values Removed Values Added
Description Authentication Bypass Using an Alternate Path or Channel vulnerability in Iulia Cazan Emails Catch All emails-catch-all allows Password Recovery Exploitation.This issue affects Emails Catch All: from n/a through <= 3.5.3.
Title WordPress Emails Catch All plugin <= 3.5.3 - Broken Authentication vulnerability
Weaknesses CWE-288
References

Subscriptions

Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-04-28T16:13:52.990Z

Reserved: 2025-09-25T15:19:17.076Z

Link: CVE-2025-60041

cve-icon Vulnrichment

Updated: 2025-10-23T13:20:51.183Z

cve-icon NVD

Status : Deferred

Published: 2025-10-22T15:15:56.660

Modified: 2026-06-17T09:49:14.923

Link: CVE-2025-60041

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-04-30T05:45:16Z

Weaknesses
  • CWE-288

    Authentication Bypass Using an Alternate Path or Channel