Project Subscriptions
No advisories yet.
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
Wed, 18 Feb 2026 13:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Wed, 18 Feb 2026 11:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Roxnor
Roxnor emailkit – Email Customizer For Woocommerce & Wp Wordpress Wordpress wordpress |
|
| Vendors & Products |
Roxnor
Roxnor emailkit – Email Customizer For Woocommerce & Wp Wordpress Wordpress wordpress |
Wed, 18 Feb 2026 05:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | The EmailKit – Email Customizer for WooCommerce & WP plugin for WordPress is vulnerable to unauthorized data modification due to a missing capability check on the 'update_template_data' function in all versions up to, and including, 1.6.2. This makes it possible for authenticated attackers, with Subscriber-level access and above, to modify the title of any post on the site, including posts, pages, and custom post types. | |
| Title | EmailKit – Email Customizer for WooCommerce & WP <= 1.6.2 - Missing Authorization to Authenticated (Subscriber+) Arbitrary Post Title Modification | |
| Weaknesses | CWE-862 | |
| References |
|
|
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: Wordfence
Published:
Updated: 2026-02-18T12:53:36.600Z
Reserved: 2026-02-04T19:32:44.061Z
Link: CVE-2026-1925
Updated: 2026-02-18T12:25:27.308Z
Status : Received
Published: 2026-02-18T05:16:28.803
Modified: 2026-02-18T05:16:28.803
Link: CVE-2026-1925
No data.
OpenCVE Enrichment
Updated: 2026-02-18T10:32:50Z