Description
The WP Mail Logging WordPress plugin before 1.17.0 does not properly restrict the HTML and CSS of logged emails before rendering them in its admin log screens, allowing unauthenticated users to inject styled content and links, for example through a public contact form, that can deceive an administrator viewing the log and send their browser to an attacker-controlled page.
Published: 2026-10-02
Score: 4.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Unauthenticated HTML Injection
Action: Update Plugin
AI Analysis

Impact

WP Mail Logging WordPress plugin versions before 1.17.0 fail to filter HTML and CSS from logged emails before rendering them in the administration log screens. Unauthenticated users can inject styled content and links, for example via a public contact form, that will be rendered when an administrator views the log. This can deceive administrators into clicking attacker‑controlled links or expose phishing content.

Affected Systems

The vulnerability affects installations of the WP Mail Logging plugin older than version 1.17.0 on WordPress sites that use the plugin to log incoming emails. Any site with a public contact form that triggers logging is vulnerable; unauthenticated users can submit payloads, while administrators who view the logs experience the injected content.

Risk and Exploitability

With a CVSS score of 4.3 the flaw is considered a moderate risk. The EPSS score is not listed but the vulnerability relies on unauthenticated form submission and then requires an administrator to view the logs to be compromised, which limits immediate exploitation. Since it is not included in the CISA KEV catalog, no known public exploits exist, but the potential for phishing or link redirection remains significant for sites that expose the log to admins.

Generated by OpenCVE AI on October 2, 2026 at 08:49 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Update WP Mail Logging to version 1.17.0 or later which sanitizes logged email content before display.
  • If an update is not immediately possible, disable the logging of email content or restrict log visibility to administrators only.
  • Implement a server‑side sanitization routine that strips or escapes HTML tags from email bodies before they are stored or displayed in the log.

Generated by OpenCVE AI on October 2, 2026 at 08:49 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 02 Oct 2026 11:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 02 Oct 2026 09:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-74
CWE-79

Fri, 02 Oct 2026 07:15:00 +0000

Type Values Removed Values Added
Description The WP Mail Logging WordPress plugin before 1.17.0 does not properly restrict the HTML and CSS of logged emails before rendering them in its admin log screens, allowing unauthenticated users to inject styled content and links, for example through a public contact form, that can deceive an administrator viewing the log and send their browser to an attacker-controlled page.
Title WP Mail Logging < 1.17.0 - Unauthenticated HTML Injection
References
Metrics cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: WPScan

Published:

Updated: 2026-10-02T10:54:10.923Z

Reserved: 2026-01-29T20:06:22.522Z

Link: CVE-2026-1661

cve-icon Vulnrichment

Updated: 2026-10-02T10:44:44.299Z

cve-icon NVD

Status : Received

Published: 2026-10-02T07:16:36.673

Modified: 2026-10-02T11:17:34.360

Link: CVE-2026-1661

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-02T09:00:18Z

Weaknesses
  • CWE-74

    Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')

  • CWE-79

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')