Impact
The CatalogX WordPress plugin before version 6.1.3 improperly stores data supplied by unauthenticated users into a shared transient without sanitizing or escaping it. When a product enquiry notification email is later constructed for the site administrator, the unsanitized content is embedded directly into that email, allowing an attacker to inject arbitrary text. This can be exploited to forge email headers, send phishing messages, or otherwise manipulate the email content sent to the administrator.
Affected Systems
Any WordPress site that has the CatalogX plugin installed with a version older than 6.1.3 is vulnerable.
Risk and Exploitability
The vulnerability can be triggered over the public web without needing authentication; an attacker can create a malicious transient entry and then wait for an unrelated visitor to submit a product enquiry, at which point the crafted email is dispatched. No EPSS or KEV scores are reported, but the flaw is unauthenticated and can lead to spoofed or compromised administrator emails, representing a significant threat to confidentiality and trust in the site’s communication channel.
OpenCVE Enrichment