Impact
The WordPress Email Log plugin, versions 2.63 and earlier, contains an administrator-level SQL Injection flaw that permits an authenticated administrator to inject arbitrary SQL statements through the plugin’s interface. This vulnerability can lead to unauthorized disclosure or modification of the site’s database, potentially exposing sensitive email logs or allowing destructive changes to critical data.
Affected Systems
All installations of WebFactory’s Email Log plugin for WordPress running version 2.63 or earlier are vulnerable. This includes any WordPress site that has not applied the public update to 2.64 or newer.
Risk and Exploitability
The CVSS score of 7.6 indicates high severity, although the EPSS score is not available, leaving the exploitation probability unclear. The vulnerability is not listed in the CISA KEV catalog. The likely attack vector is via the WordPress admin interface, where an authenticated attacker with administrative rights can submit crafted input to the plugin and exploit the flaw. Because only administrators can trigger the injection, the threat is limited to sites where compromised credentials or social engineering give an attacker admin access.
OpenCVE Enrichment