Sceawere
Vulnerability Detail
CVE-2026-1661UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
WP Mail Logging Stored XSS
Vulnerability Metadata
- Severity
- Medium
- Score / CVSS
- 4.3
- Creation Date
- 16h ago
- Vendor
- Unknown
- Product
- WP Mail Logging
- Attack Type
- CWE-79 Cross-Site Scripting (XSS)
- Vector String
- CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N
- Attack Complexity
- LOW
Narrative and Response
Description
The WP Mail Logging WordPress plugin before 1.17.0 does not properly restrict the HTML and CSS of logged emails before rendering them in its admin log screens, allowing unauthenticated users to inject styled content and links, for example through a public contact form, that can deceive an administrator viewing the log and send their browser to an attacker-controlled page.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "4.3",
"pubDate": "2026-10-02T07:16:36.673Z",
"pubdate": "2026-10-02T07:16:36.673Z",
"executiveSummary": "The WP Mail Logging WordPress plugin prior to version 1.17.0 contains a Stored Cross-Site Scripting (XSS) vulnerability within its administrative logging interface.\nThe vulnerability stems from the improper sanitization of email content, specifically HTML and CSS, which is rendered directly into the admin dashboard without sufficient output encoding.\nAn unauthenticated attacker can exploit this by submitting malicious payloads through public-facing mechanisms, such as contact forms, which the plugin subsequently logs.\nWhen an administrator navigates to the plugin's log screens, the browser executes the injected malicious script or renders the deceptive content.\nThis vulnerability poses a significant risk as it allows for unauthorized actions, session hijacking, or redirection of administrators to attacker-controlled domains.\nSuccessful exploitation requires no authentication from the attacker, relying solely on the victim's interaction with the administrative logging interface.",
"technicalDetails": "The root cause of this vulnerability is the lack of server-side sanitization or output escaping for HTML and CSS payloads processed by the WP Mail Logging plugin before rendering them in the administrative log view.\nBecause the plugin logs the entirety of the email's body—which may include user-supplied input from web forms—the absence of input validation allows for the injection of arbitrary HTML tags and malicious CSS styles.\nThe attack flow begins with an unauthenticated user interacting with a publicly accessible input vector, such as a website contact form that triggers an email notification processed by the plugin.\nThe attacker embeds a malicious payload, such as a <script> tag or an <a> element with an 'onmouseover' event handler, into the input fields. Since these fields are not sanitized, the malicious code is stored within the plugin's underlying database tables.\nThe exploitation stage occurs when a WordPress administrator accesses the WP Mail Logging interface within the administrative dashboard. The plugin retrieves the stored, malicious email record from the database and renders the raw content directly into the DOM of the admin panel.\nWhen the administrator's browser parses the malicious HTML, it executes the injected JavaScript within the context of the WordPress admin session. This allows the attacker to execute arbitrary actions on behalf of the administrator, such as creating new administrative accounts, modifying plugin configurations, or exfiltrating sensitive session tokens.\nFurthermore, the ability to inject custom CSS allows attackers to manipulate the visual presentation of the administrative interface. Attackers can use this to spoof UI elements, creating deceptive links or fake security prompts that trick the administrator into navigating to an external, attacker-controlled malicious domain.\nThe vulnerability affects all versions of the WP Mail Logging plugin prior to 1.17.0. Because the logging mechanism is a core feature of the plugin, the exposure is inherent to the product's design in affected versions. No specific administrative privileges are required for the attacker to inject the payload, as the primary constraint is simply the ability to trigger a logged email event."
}