{“error”:0,”message”:null,”data”:{“name”:”WP Mail Logging”,”plugin”:”wp-mail-logging”,”link”:”https:\/\/wordpress.org\/plugins\/wp-mail-logging\/”,”latest”:”1735547400″,”closed”:0,”vulnerability”:[{“uuid”:”80c7042ffb195acfb1866b0a782f0b2a5e270b2bad6606a672fbabc8d07e5ef1″,”name”:”WP Mail Logging [wp-mail-logging] < 1.10.0","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"1.10.0","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2021-38314","name":"CVE-2021-38314","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2021-38314","description":"[en] The Gutenberg Template Library & Redux Framework plugin <= 4.2.11 for WordPress registered several AJAX actions available to unauthenticated users in the `includes` function in `redux-core\/class-redux-core.php` that were unique to a given site but deterministic and predictable given that they were based on an md5 hash of the site URL with a known salt value of '-redux' and an md5 hash of the previous hash with a known salt value of '-support'. These AJAX actions could be used to retrieve a list of active plugins and their versions, the site's PHP version, and an unsalted md5 hash of site\u2019s `AUTH_KEY` concatenated with the `SECURE_AUTH_KEY`.","date":"2021-09-02"},{"id":"50d1418939300e597999aea9ea6af7d11614a190","name":"WordPress WP Mail Logging plugin <= 1.9.9 - Using Components with Known Vulnerabilities (vulnerable Redux Framework version)","link":"https:\/\/patchstack.com\/database\/wordpress\/plugin\/wp-mail-logging\/vulnerability\/wordpress-wp-mail-logging-plugin-1-9-9-using-components-with-known-vulnerabilities-vulnerable-redux-framework-version","description":"Using Components with Known Vulnerabilities (vulnerable Redux Framework version - CVE-2021-38312, CVE-2021-38314) discovered by Rotem Reiss in WordPress WP Mail Logging plugin (versions <= 1.9.9).","date":"2021-11-29"},{"id":"66616623-0c80-4b95-a8de-5d7f8c6a57b3","name":"WP Mail Logging < 1.10.0 - Outdated Redux Framework","link":"https:\/\/wpscan.com\/vulnerability\/66616623-0c80-4b95-a8de-5d7f8c6a57b3","description":"The plugin uses an outdated version of the Redux Framework, which is know to be affected by security issues (CVE-2021-38312 and CVE-2021-38314), and could allow unauthenticated attackers to change some of the Framework settings by using CVE-2021-38314","date":null}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:N\/UI:N\/S:U\/C:L\/I:N\/A:N","av":"n","ac":"l","pr":"n","ui":"n","s":"u","c":"l","i":"n","a":"n","score":"5.3","severity":"m","exploitable":"0.0","impact":"0.0"},"cwe":[{"cwe":"CWE-200","name":"Exposure of Sensitive Information to an Unauthorized Actor","description":"The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information."},{"cwe":"CWE-760","name":"Use of a One-Way Hash with a Predictable Salt","description":"The product uses a one-way cryptographic hash against an input that should not be reversible, such as a password, but the product uses a predictable salt as part of the input."}]}},{"uuid":"363caa2a5332459b48ee2dea1d797b879a83a37f55845861d73ea1a8a85e3190","name":"WP Mail Logging [wp-mail-logging] < 1.8.3","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"1.8.3","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"f673de5eace2d78fe63138c4deed53981120c95f","name":"WordPress WP Mail Logging plugin <=1.8.2 - Stored Cross-Site Scripting (XSS) vulnerability","link":"https:\/\/patchstack.com\/database\/wordpress\/plugin\/wp-mail-logging\/vulnerability\/wordpress-wp-mail-logging-plugin-1-8-2-stored-cross-site-scripting-xss-vulnerability","description":"Stored Cross-Site Scripting (XSS) vulnerability found by Yehuda in WordPress WP Mail Logging plugin (versions <=1.8.2).","date":"2017-11-20"}],"impact":[]},{"uuid":"9c9a1516219d86fd2b7f5055c512176bd0cda419d8c0af9d9016f234566dc44a","name":"WP Mail Logging [wp-mail-logging] < 1.10.0","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"1.10.0","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"ff320b0a3bb93f100730eeb0322346e556a35a21","name":"WP Mail Logging < 1.10.0 - Unauthenticated Arbitrary Settings Change","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/wp-mail-logging\/wp-mail-logging-1100-unauthenticated-arbitrary-settings-change","description":"The WP Mail Logging plugin for WordPress is vulnerable to arbitrary settings change in versions before 1.10.0. This is due to the plugin using an outdated version of the Redux Framework. This makes it possible for unauthenticated attackers to arbitrarily change some plugin settings.","date":"2021-11-29"}],"impact":[]},{"uuid":"54ad96400c9bb65465dcb65894fd9d3a176697af2aea29d56b79b1162c3166be","name":"WP Mail Logging [wp-mail-logging] < 1.8.3","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"1.8.3","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"16a4582a65ef1c749500b25a8972af811c2b8de7","name":"WP Mail Logging <= 1.8.2 - Cross-Site Scripting","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/wp-mail-logging\/wp-mail-logging-182-cross-site-scripting","description":"The WP Mail Logging plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the \u2018extractMessage\u2019 and 'column_default' functions in versions up to, and including, 1.8.2 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.","date":"2017-11-11"}],"impact":[]},{"uuid":"d97220dd16c51de681b00efb4884b5d7966182e8c89a16321c80550552d2e2da","name":"WP Mail Logging [wp-mail-logging] < 1.11.0","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"1.11.0","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2022-47150","name":"CVE-2022-47150","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2022-47150","description":"** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided.","date":null},{"id":"9661aa524289f81dc7a97dbf79c3ab673170e128","name":"WordPress WP Mail Logging Plugin <= 1.10.5 is vulnerable to Cross Site Request Forgery (CSRF)","link":"https:\/\/patchstack.com\/database\/wordpress\/plugin\/wp-mail-logging\/vulnerability\/wordpress-wp-mail-logging-plugin-1-10-5-cross-site-request-forgery-csrf-vulnerability","description":"Update the WordPress WP Mail Logging plugin to the latest available version (at least 1.11.0).\nLana Codes discovered and reported this Cross Site Request Forgery (CSRF) vulnerability in WordPress WP Mail Logging Plugin. This could allow a malicious actor to force higher privileged users to execute unwanted actions under their current authentication. This vulnerability has been fixed in version 1.11.0.","date":"2023-03-21"}],"impact":[]},{"uuid":"cbb3436d3029e1c157ae93a3493ace15172def360301944c0cf186acd7033c70","name":"WP Mail Logging [wp-mail-logging] < 1.11.2","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"1.11.2","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2023-3081","name":"CVE-2023-3081","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2023-3081","description":"[en] The WP Mail Logging plugin for WordPress is vulnerable to Stored Cross-Site Scripting via email contents in versions up to, and including, 1.11.1 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. Note: An incomplete fix was released in 1.11.1.","date":"2023-07-12"},{"id":"2f62b0b4a040fa995bdec41c2bc552a6ac967d80","name":"WP Mail Logging <= 1.11.1 - Unauthenticated Stored Cross-Site Scripting via Email","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/wp-mail-logging\/wp-mail-logging-1110-unauthenticated-stored-cross-site-scripting-via-email","description":"The WP Mail Logging plugin for WordPress is vulnerable to Stored Cross-Site Scripting via email contents in versions up to, and including, 1.11.1 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. Note: An incomplete fix was released in 1.11.1.","date":"2023-06-08"},{"id":"bbeda873adba71a15e1c10f89d360772f88c9cdd","name":"WordPress WP Mail Logging Plugin <= 1.11.0 is vulnerable to Cross Site Scripting (XSS)","link":"https:\/\/patchstack.com\/database\/wordpress\/plugin\/wp-mail-logging\/vulnerability\/wordpress-wp-mail-logging-plugin-1-11-0-unauthenticated-stored-cross-site-scripting-via-email-vulnerability","description":"Update the WordPress WP Mail Logging plugin to the latest available version (at least 1.11.1).\nAlex Thomas discovered and reported this Cross Site Scripting (XSS) vulnerability in WordPress WP Mail Logging Plugin. This could allow a malicious actor to inject malicious scripts, such as redirects, advertisements, and other HTML payloads into your website which will be executed when guests visit your site. This vulnerability has been fixed in version 1.11.1.","date":"2023-06-12"},{"id":"34e9d9a7-3d2f-432b-9b7f-645c0472e399","name":"WP Mail Logging < 1.11.2 - Unauthenticated Stored Cross-Site Scripting","link":"https:\/\/wpscan.com\/vulnerability\/34e9d9a7-3d2f-432b-9b7f-645c0472e399","description":"The plugin does not adequately sanitize and escape email contents, enabling the injection of arbitrary web scripts into pages.","date":null}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:N\/UI:N\/S:C\/C:L\/I:L\/A:N","av":"n","ac":"l","pr":"n","ui":"n","s":"c","c":"l","i":"l","a":"n","score":"7.2","severity":"h","exploitable":"0.0","impact":"0.0"},"cwe":[{"cwe":"CWE-79","name":"Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')","description":"The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users."}]}},{"uuid":"7b15cabbf558e77c976d17af4ce529f487181f4232802b24fdfe8385ce5a2cf8","name":"WP Mail Logging [wp-mail-logging] < 1.12.0","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"1.12.0","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"25792919c2f5c1af94cee76ff90b5871ca0d7e37","name":"WP Mail Logging <= 1.11.2 - Missing Authorization to Notice Dismissal","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/wp-mail-logging\/wp-mail-logging-1112-missing-authorization-to-notice-dismissal","description":"The WP Mail Logging plugin for WordPress is vulnerable to unauthorized notice dismissal due to a missing capability check on the feedback_notice_dismiss() function in versions up to, and including, 1.11.2. This makes it possible for authenticated attackers with subscriber-level access and above to dismiss plugin notices.","date":"2023-06-23"}],"impact":[]},{"uuid":"020787f40d4fdbe6de792884a7892ba86a7805c27efd3083ff397c9ce5282553","name":"WP Mail Logging [wp-mail-logging] < 1.12.0","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"1.12.0","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"0cc11fdb666f5be9bc661517d8e97abf61e68bbc","name":"WordPress WP Mail Logging Plugin < 1.12.0 is vulnerable to Broken Access Control","link":"https:\/\/patchstack.com\/database\/wordpress\/plugin\/wp-mail-logging\/vulnerability\/wordpress-wp-mail-logging-plugin-1-11-2-missing-authorization-to-notice-dismissal-vulnerability","description":"Update the WordPress WP Mail Logging plugin to the latest available version (at least 1.12.0).\nUnknown discovered and reported this Broken Access Control vulnerability in WordPress WP Mail Logging Plugin. This vulnerability has been fixed in version 1.12.0.","date":"2023-06-26"}],"impact":[]},{"uuid":"b4e66c43d3056bd7648bd7cb79ba476e799cac14a386302943484936e53fb725","name":"WP Mail Logging [wp-mail-logging] < 1.8.3","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"1.8.3","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"8ff377db-08f9-4d98-af49-43dcbfcd98b5","name":"WP Mail Logging <= 1.8.2 - Stored Cross-Site Scripting","link":"https:\/\/wpscan.com\/vulnerability\/8ff377db-08f9-4d98-af49-43dcbfcd98b5","description":"The WP Mail Logging by MailPoet WordPress plugin was affected by a Stored Cross-Site Scripting security vulnerability.","date":null}],"impact":[]}]},"updated":"1750132204"}