Description
Administrator SQL Injection in Email Log <= 2.63 versions.
Published: 2026-09-23
Score: 7.6 High
EPSS: n/a
KEV: No
Impact: SQL Injection
Action: Apply Patch
AI Analysis

Impact

The WordPress Email Log plugin, versions 2.63 and earlier, contains an administrator-level SQL Injection flaw that permits an authenticated administrator to inject arbitrary SQL statements through the plugin’s interface. This vulnerability can lead to unauthorized disclosure or modification of the site’s database, potentially exposing sensitive email logs or allowing destructive changes to critical data.

Affected Systems

All installations of WebFactory’s Email Log plugin for WordPress running version 2.63 or earlier are vulnerable. This includes any WordPress site that has not applied the public update to 2.64 or newer.

Risk and Exploitability

The CVSS score of 7.6 indicates high severity, although the EPSS score is not available, leaving the exploitation probability unclear. The vulnerability is not listed in the CISA KEV catalog. The likely attack vector is via the WordPress admin interface, where an authenticated attacker with administrative rights can submit crafted input to the plugin and exploit the flaw. Because only administrators can trigger the injection, the threat is limited to sites where compromised credentials or social engineering give an attacker admin access.

Generated by OpenCVE AI on September 23, 2026 at 20:13 UTC.

Remediation

Vendor Solution

Update the WordPress Email Log plugin to the latest available version (at least 2.64).


OpenCVE Recommended Actions

  • Update the WordPress Email Log plugin to version 2.64 or newer.
  • Disable or remove the Email Log plugin if it is not required for site functionality to eliminate the attack surface.
  • Limit administrative access to the WordPress backend by enforcing strong, unique passwords, two‑factor authentication, and restricting login attempts.

Generated by OpenCVE AI on September 23, 2026 at 20:13 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 23 Sep 2026 18:30:00 +0000

Type Values Removed Values Added
Description Administrator SQL Injection in Email Log <= 2.63 versions.
Title WordPress Email Log plugin <= 2.63 - SQL Injection vulnerability
Weaknesses CWE-89
References
Metrics cvssV3_1

{'score': 7.6, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:N/A:L'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-09-23T18:54:11.830Z

Reserved: 2026-09-21T00:20:20.798Z

Link: CVE-2026-94174

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Deferred

Published: 2026-09-23T19:19:48.277

Modified: 2026-09-23T19:39:08.847

Link: CVE-2026-94174

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-23T20:15:09Z

Weaknesses
  • CWE-89

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')