Impact
WP Mail Logging WordPress plugin versions before 1.17.0 fail to filter HTML and CSS from logged emails before rendering them in the administration log screens. Unauthenticated users can inject styled content and links, for example via a public contact form, that will be rendered when an administrator views the log. This can deceive administrators into clicking attacker‑controlled links or expose phishing content.
Affected Systems
The vulnerability affects installations of the WP Mail Logging plugin older than version 1.17.0 on WordPress sites that use the plugin to log incoming emails. Any site with a public contact form that triggers logging is vulnerable; unauthenticated users can submit payloads, while administrators who view the logs experience the injected content.
Risk and Exploitability
With a CVSS score of 4.3 the flaw is considered a moderate risk. The EPSS score is not listed but the vulnerability relies on unauthenticated form submission and then requires an administrator to view the logs to be compromised, which limits immediate exploitation. Since it is not included in the CISA KEV catalog, no known public exploits exist, but the potential for phishing or link redirection remains significant for sites that expose the log to admins.
OpenCVE Enrichment