Impact
The CatalogX WordPress plugin before version 6.1.3 stores user supplied data in a shared transient without sanitizing or escaping it. When an unrelated visitor submits a product enquiry, the plugin includes that stored content directly into the product enquiry notification email sent to the site administrator. Based on the description, it is inferred that an attacker may inject arbitrary text, possibly forging email headers or inserting malicious links, thereby compromising the integrity and authenticity of administrative notifications. This flaw does not provide code execution or denial‑of‑service, but it enables email‑based social engineering attacks.
Affected Systems
Any WordPress installation that has the CatalogX plugin installed with a version older than 6.1.3 is affected. The CNA identifies the product as “CatalogX Web‑Product Plug‑in”. No additional patch release numbers are listed beyond the fact that versions prior to 6.1.3 are vulnerable, so administrators should check whether their site is running a vulnerable version.
Risk and Exploitability
The CVSS score of 4.3 indicates a medium impact focused on email integrity, while the EPSS score of <1% shows a very low but non‑zero exploitation probability. The likely attack vector is a remote, unauthenticated web input that creates the shared transient; the flaw only manifests when a subsequent product enquiry triggers the email. Because the attacker must wait for a user action to send the email, widespread exploitation is unlikely, and the flaw is not currently listed in the CISA KEV catalog. Nevertheless, any public WordPress site using the affected plugin should monitor for anomalous email content and respond promptly if the vulnerability is exploited.
OpenCVE Enrichment