PT-2026-35668 · WordPress · Check & Log Email

Matthew Rollings

·

Published

2026-04-28

·

Updated

2026-04-28

·

CVE-2026-5306

CVSS v3.1

5.4

Medium

VectorAV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Check & Log Email WordPress plugin versions prior to 2.0.13
Description Improper handling of email replacement allows unauthenticated users to perform Stored Cross-Site Scripting (XSS) attacks when the email encoder setting is enabled. Stored XSS occurs when a malicious script is permanently stored on the target server, which is then served to other users.
Recommendations Update the plugin to version 2.0.13 or later.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2026-5306

Affected Products

Check & Log Email