PT-2026-52213 · WordPress · Email-Encoder-Premium+1

·

CVE-2026-5305

·

Published

2026-06-25

·

Updated

2026-06-25

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Email Address Encoder versions prior to 1.0.25 email-encoder-premium versions prior to 0.3.12
Description Improper handling of email replacement allows unauthenticated users to perform Stored Cross-Site Scripting (XSS) attacks. This issue occurs due to unsafe handling of email replacement output and improper input validation or output encoding, which allows attacker-controlled content to be persisted and rendered as a script. An attacker can remotely inject crafted payloads during the email replacement process that are later served to visitors or administrators. This can lead to arbitrary JavaScript execution in the victim's browser, potentially resulting in administrative session hijacking, malicious redirects, and site takeover.
Recommendations Update Email Address Encoder to version 1.0.25. Update email-encoder-premium to version 0.3.12.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2026-5305

Affected Products

Email Address Encoder
Email-Encoder-Premium