Impact
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in weDevs weMail wemail allows reflected XSS. The flaw affects weMail from n/a through 2.1.2 and is triggered by unescaped user‑supplied data rendered in the plugin’s front‑end. This allows an attacker to inject malicious scripts into a page viewed by unsuspecting users. The vulnerability is a classic input‑sensitivity problem (CWE‑79) that can be leveraged to steal session cookies, deface content, or launch phishing attacks. Because the flaw is in the plugin’s front‑end, any user who accesses the affected page can trigger it.
Affected Systems
The affected product is the weMail plugin for WordPress, developed by weDevs. Versions up to and including 2.1.2 are vulnerable; the latest release 2.1.3 contains the fix.
Risk and Exploitability
The CVSS score of 7.1 marks it as high severity. The EPSS score of 0.00251 (0.251%) indicates a very low exploitation probability, although the vulnerability is unauthenticated and could be triggered by any user who receives a crafted request. The vulnerability is not listed in CISA’s KEV catalog, indicating it has not yet been widely abused in the wild. An attacker can send a crafted URL to an end‑user that triggers the reflected payload, causing the browser to execute arbitrary JavaScript.
OpenCVE Enrichment