Impact
The WP Mail Catcher plugin stores PHPMailer error messages when email delivery fails. Because the plugin does not sanitize or escape the content of these messages, an attacker can embed arbitrary JavaScript into the error message. The message is written to a persistent log and later displayed in the WordPress admin pages, meaning the script is stored and executed whenever a user views the log entry. This stored cross‑site scripting can allow the attacker to steal cookies, hijack sessions, deface the site, or launch phishing attacks from the victim’s browser.
Affected Systems
The vulnerability affects the Mail logging – WP Mail Catcher WordPress plugin, versions up to and including 2.1.12. It requires the plugin to be installed on a WordPress site that also has a mail‑sending add‑on such as Contact Form 7 or another plugin that passes unauthenticated user data into email fields. The vendor identified by the CNA is wardee:Mail logging & Catcher.
Risk and Exploitability
The CVSS score of 7.2 indicates moderate‑to‑high severity. EPSS data is not available, and the issue is not currently listed in the CISA KEV catalog, suggesting that large‑scale exploitation has not yet been observed. Nonetheless, any site that uses the vulnerable plugin version together with a form‑handling plugin can be targeted: an unauthenticated attacker can craft input that triggers a PHPMailer failure and inject malicious script into the stored log. When an authenticated user later opens the log page, the stored script will execute in their browser. The risk is therefore moderate for environments running the affected plugin without a mitigated logging configuration.
OpenCVE Enrichment