Sceawere
Vulnerability Detail
CVE-2026-93889UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
WP Mail Catcher Stored XSS
Vulnerability Metadata
- Severity
- High
- Score / CVSS
- 7.2
- Creation Date
- 3h ago
- Vendor
- wardee
- Product
- Mail logging & Catcher
- Attack Type
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
- Vector String
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N
- Attack Complexity
- LOW
Narrative and Response
Description
The Mail logging – WP Mail Catcher plugin for WordPress is vulnerable to Stored Cross-Site Scripting via PHPMailer 'wp_mail_failed' Error Message in all versions up to, and including, 2.1.12 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. Successful exploitation requires a separately installed plugin, such as Contact Form 7, that passes unauthenticated user-controlled input into mail fields whose content PHPMailer will include in its failure error message.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "7.2",
"pubDate": "2026-10-03T07:16:48.680Z",
"pubdate": "2026-10-03T07:16:48.680Z",
"executiveSummary": "The WP Mail Catcher WordPress plugin is susceptible to Stored Cross-Site Scripting (XSS) due to improper handling of error messages generated by PHPMailer via the 'wp_mail_failed' hook.\nThis vulnerability allows unauthenticated attackers to inject malicious JavaScript into the plugin's logging interface. When an administrator or privileged user views the logs, the payload executes within their browser session.\nThe vulnerability affects all versions of the WP Mail Catcher plugin up to and including 2.1.12.\nThe impact includes potential unauthorized actions performed on behalf of the administrator, session hijacking, or exfiltration of sensitive configuration data.\nSuccessful exploitation requires the presence of a secondary vector, such as a contact form plugin, that passes unauthenticated user-supplied input into the mail delivery process, which then triggers the vulnerable error logging mechanism.\nThis represents a significant security risk, as the execution of arbitrary scripts in an administrative context can lead to full site compromise.",
"technicalDetails": "The root cause of this vulnerability lies in the insufficient input sanitization and output escaping of error data handled by the WP Mail Catcher plugin. Specifically, the plugin hooks into the 'wp_mail_failed' action, which captures details regarding failed mail delivery attempts initiated by WordPress core or third-party plugins.\nWhen PHPMailer encounters an error, it provides a message containing parameters passed to the wp_mail() function. If an attacker submits a form (e.g., via Contact Form 7) containing malicious script tags in fields such as the 'Subject' or 'Message' body, and that email delivery fails, the resulting error message—containing the raw, unencoded malicious input—is stored in the WP Mail Catcher database.\nThe attack flow proceeds as follows: First, an unauthenticated attacker crafts a request to a public-facing form containing a JavaScript payload. Second, the attacker triggers an event that causes the mail delivery to fail (e.g., by providing an invalid recipient address or triggering a server-side mail configuration error). Third, the WordPress application invokes the 'wp_mail_failed' hook. Fourth, the WP Mail Catcher plugin retrieves the error context, including the user-controlled input, and saves it into the logging table without performing adequate output encoding or sanitization.\nFinally, when an administrator navigates to the WP Mail Catcher logs within the WordPress dashboard, the plugin renders the stored error message directly into the Document Object Model (DOM) of the management page. Because the browser interprets this injected content as executable code rather than plain text, the malicious script runs with the privileges of the logged-in administrative user.\nThis stored XSS vulnerability is particularly dangerous because it bypasses standard authentication requirements for the administrative interface by leveraging a secondary, publicly accessible input vector. Since the payload is stored persistently in the database, the script will execute every time the administrative log view is rendered until the entry is purged.\nThe affected component is the internal logging routine that processes error data from the 'wp_mail_failed' hook. No authentication or specific privileges are required to initiate the injection, as the trigger occurs through public form submissions. Post-exploitation impact is limited only by the permissions of the user viewing the logs, typically resulting in full administrative control over the WordPress installation via the execution of arbitrary administrative actions or the injection of persistent malicious backdoors."
}