high · CVSS v3 7.2 · EPSS 0.00241
CVE-2026-93889
WP Mail Catcher plugin for WordPress contains a stored XSS flaw via PHPMailer error messages. Unauthenticated attackers can inject scripts t
Overview
WP Mail Catcher plugin for WordPress contains a stored XSS flaw via PHPMailer error messages. Unauthenticated attackers can inject scripts that execute when users view affected pages. The vulnerability requires another plugin, such as Contact Form 7, to pass user input into mail fields.
Description
The Mail logging – WP Mail Catcher plugin for WordPress is vulnerable to Stored Cross-Site Scripting via PHPMailer 'wp_mail_failed' Error Message in all versions up to, and including, 2.1.12 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. Successful exploitation requires a separately installed plugin, such as Contact Form 7, that passes unauthenticated user-controlled input into mail fields whose content PHPMailer will include in its failure error message.
Impact
Confidentiality: injected scripts can expose user data. Integrity: malicious code can alter page content. Availability: minimal impact. Impacted parties: WordPress site owners, administrators, and end users who view affected pages.
Remediation
Update WP Mail Catcher to the latest version (≥2.1.13). Sanitize PHPMailer error messages or disable error output. Remove or disable unused mail plugins. Apply WAF rules to block XSS payloads. Monitor logs for failed mail attempts.
Risk context
High severity with an EPSS of 0.00241 indicates a rare but serious vulnerability; defenders should patch promptly.
Affected products
- WordPress WP Mail Catcher
- Contact Form 7
- PHPMailer
Scores
- Severity
- high
- CVSS v2
- 6.4
- CVSS v3
- 7.2
- CVSS v4
- —
- EPSS
- 0.00241