Impact
The Check & Log Email plugin fails to properly sanitize or encode email replacement content when the email encoder setting is active, allowing an unauthenticated user to inject malicious script data that is stored in the database and executed when a user later views a page. This stored XSS flaw can be used to hijack user sessions, deface pages, or deliver malware to site visitors.
Affected Systems
Any WordPress site running the Check & Log Email plugin version earlier than 2.0.13 is affected. No operating‑system or WordPress core exclusions are specified.
Risk and Exploitability
The CVSS score for this vulnerability is 5.4, while the EPSS score is less than 1 %. It is not listed in the CISA KEV catalog. Exploitation requires no authentication and relies solely on the public email replacement interface of the plugin. Because the payload is stored and served to all users, an attacker can impact the entire audience of the affected WordPress site.
OpenCVE Enrichment