rootpwn

high · CVSS v3 7.2 · EPSS 0.00241

CVE-2026-93889

WP Mail Catcher plugin for WordPress contains a stored XSS flaw via PHPMailer error messages. Unauthenticated attackers can inject scripts t

Overview

WP Mail Catcher plugin for WordPress contains a stored XSS flaw via PHPMailer error messages. Unauthenticated attackers can inject scripts that execute when users view affected pages. The vulnerability requires another plugin, such as Contact Form 7, to pass user input into mail fields.

Description

The Mail logging – WP Mail Catcher plugin for WordPress is vulnerable to Stored Cross-Site Scripting via PHPMailer 'wp_mail_failed' Error Message in all versions up to, and including, 2.1.12 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. Successful exploitation requires a separately installed plugin, such as Contact Form 7, that passes unauthenticated user-controlled input into mail fields whose content PHPMailer will include in its failure error message.

Impact

Confidentiality: injected scripts can expose user data. Integrity: malicious code can alter page content. Availability: minimal impact. Impacted parties: WordPress site owners, administrators, and end users who view affected pages.

Remediation

Update WP Mail Catcher to the latest version (≥2.1.13). Sanitize PHPMailer error messages or disable error output. Remove or disable unused mail plugins. Apply WAF rules to block XSS payloads. Monitor logs for failed mail attempts.

Risk context

High severity with an EPSS of 0.00241 indicates a rare but serious vulnerability; defenders should patch promptly.

Affected products

  • WordPress WP Mail Catcher
  • Contact Form 7
  • PHPMailer

Scores

Severity
high
CVSS v2
6.4
CVSS v3
7.2
CVSS v4
—
EPSS
0.00241

XSS WordPress PHPMailer Stored XSS Mail Plugin High Severity EPSS

← All CVEs