CVE-2026-5306
MEDIUM5.4CVSS v3
—CVSS v2
0.16%
EPSS (exploit probability)
—CWE
Description
The Check & Log Email WordPress plugin before 2.0.13 does not properly handle email replacement, which could allow unauthenticated users to perform Stored XSS attacks when the email encoder setting is enabled
CVSS v3 vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
Affected routers (0)
No routers currently mapped to this CVE in our database.