Description
The Mail logging – WP Mail Catcher plugin for WordPress is vulnerable to Stored Cross-Site Scripting via PHPMailer 'wp_mail_failed' Error Message in all versions up to, and including, 2.1.12 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. Successful exploitation requires a separately installed plugin, such as Contact Form 7, that passes unauthenticated user-controlled input into mail fields whose content PHPMailer will include in its failure error message.
Published: 2026-10-03
Score: 7.2 High
EPSS: < 1% Very Low
KEV: No
Impact: Stored Cross‑Site Scripting
Action: Immediate Patch
AI Analysis

Impact

The WP Mail Catcher plugin stores PHPMailer error messages when email delivery fails. Because the plugin does not sanitize or escape the content of these messages, an attacker can embed arbitrary JavaScript into the error message. The message is written to a persistent log and later displayed in the WordPress admin pages, meaning the script is stored and executed whenever a user views the log entry. This stored cross‑site scripting can allow the attacker to steal cookies, hijack sessions, deface the site, or launch phishing attacks from the victim’s browser.

Affected Systems

The vulnerability affects the Mail logging – WP Mail Catcher WordPress plugin, versions up to and including 2.1.12. It requires the plugin to be installed on a WordPress site that also has a mail‑sending add‑on such as Contact Form 7 or another plugin that passes unauthenticated user data into email fields. The vendor identified by the CNA is wardee:Mail logging & Catcher.

Risk and Exploitability

The CVSS score of 7.2 indicates moderate‑to‑high severity. EPSS data is not available, and the issue is not currently listed in the CISA KEV catalog, suggesting that large‑scale exploitation has not yet been observed. Nonetheless, any site that uses the vulnerable plugin version together with a form‑handling plugin can be targeted: an unauthenticated attacker can craft input that triggers a PHPMailer failure and inject malicious script into the stored log. When an authenticated user later opens the log page, the stored script will execute in their browser. The risk is therefore moderate for environments running the affected plugin without a mitigated logging configuration.

Generated by OpenCVE AI on October 3, 2026 at 08:25 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade the Mail logging – WP Mail Catcher plugin to the latest release (≥2.1.13) that corrects the input sanitization and output escaping issue.
  • If an upgrade cannot be performed immediately, disable or remove the storage of PHPMailer failure messages so that unsanitized error content is no longer persisted or displayed in the admin interface.
  • Review and sanitize any additional mail‑sending plugins, such as Contact Form 7, to ensure that user‑supplied data is properly escaped before being forwarded to PHPMailer.

Generated by OpenCVE AI on October 3, 2026 at 08:25 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sat, 03 Oct 2026 16:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Sat, 03 Oct 2026 07:15:00 +0000

Type Values Removed Values Added
Description The Mail logging – WP Mail Catcher plugin for WordPress is vulnerable to Stored Cross-Site Scripting via PHPMailer 'wp_mail_failed' Error Message in all versions up to, and including, 2.1.12 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. Successful exploitation requires a separately installed plugin, such as Contact Form 7, that passes unauthenticated user-controlled input into mail fields whose content PHPMailer will include in its failure error message.
Title Mail logging <= 2.1.12 - Unauthenticated Stored Cross-Site Scripting via PHPMailer 'wp_mail_failed' Error Message
Weaknesses CWE-79
References
Metrics cvssV3_1

{'score': 7.2, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: Wordfence

Published:

Updated: 2026-10-03T15:42:42.248Z

Reserved: 2026-09-18T20:19:15.745Z

Link: CVE-2026-93889

cve-icon Vulnrichment

Updated: 2026-10-03T15:38:49.635Z

cve-icon NVD

Status : Received

Published: 2026-10-03T07:16:48.680

Modified: 2026-10-03T16:16:44.600

Link: CVE-2026-93889

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-03T08:30:18Z

Weaknesses
  • CWE-79

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')