PT-2024-31271 · WordPress · Email Encoder

Krugov Artyom

·

Published

2024-07-29

·

Updated

2025-05-29

·

CVE-2024-4483

CVSS v3.1

5.4

Medium

VectorAV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions The Email Encoder WordPress plugin versions prior to 2.2.2
Description The issue is related to a Stored Cross-Site Scripting problem. It occurs because the WP Email Encoder Bundle options[protection text] parameter is not properly escaped before being outputted back in an attribute on an admin page. This allows for malicious scripts to be stored and executed.
Recommendations For versions prior to 2.2.2, update to version 2.2.2 or later to resolve the issue. As a temporary workaround, consider restricting access to the admin page where the vulnerability occurs to minimize the risk of exploitation. Avoid using the WP Email Encoder Bundle options[protection text] parameter in the affected admin page until the issue is resolved.

Exploit

Fix

XSS

Weakness Enumeration

Related Identifiers

CVE-2024-4483

Affected Products

Email Encoder