Blog

"Prevention is cheaper than a breach"

Live Vulnerability Intelligence

Threat Database

Search CVEs, inspect descriptions, and open detail pages with AI-assisted technical context.

Total5
Critical0
High2
Medium3
Reset
Showing 1-5 of 5 records
Threat Entry Updated 2026-06-17

CVE-2026-5306 - Log Email Plugin

The Check & Log Email WordPress plugin before 2.0.13 does not properly handle email replacement, which could allow unauthenticated users to perform Stored XSS attacks when the email encoder setting is enabled

PLUGIN Log Email

CVE-2026-5306

MEDIUM CVSS 5.4 2026-04-28
Threat Entry Updated 2024-11-21

CVE-2024-0866 - Log Email Plugin

The Check & Log Email plugin for WordPress is vulnerable to Unauthenticated Hook Injection in all versions up to, and including, 1.0.9 via the check_nonce function. This makes it possible for unauthenticated attackers to execute actions with hooks in WordPress under certain circumstances. The action the attacker wishes to execute needs to have a nonce check, and the nonce needs to be known to the attacker. Furthermore, the absence of a capability check is a requirement.

PLUGIN Log Email

CVE-2024-0866

HIGH CVSS 8.1 2024-03-26
Threat Entry Updated 2024-11-21

CVE-2022-1547 - Log Email Plugin

The Check & Log Email WordPress plugin before 1.0.6 does not sanitise and escape a parameter before outputting it back in an attribute in an admin page, leading to a Reflected Cross-Site Scripting

PLUGIN Log Email

CVE-2022-1547

MEDIUM CVSS 6.1 2022-05-23
Threat Entry Updated 2024-11-21

CVE-2021-24908 - Log Email Plugin

The Check & Log Email WordPress plugin before 1.0.4 does not escape the d parameter before outputting it back in an attribute, leading to a Reflected Cross-Site Scripting

PLUGIN Log Email

CVE-2021-24908

MEDIUM CVSS 6.1 2021-11-29
Threat Entry Updated 2024-11-21

CVE-2021-24774 - Log Email Plugin

The Check & Log Email WordPress plugin before 1.0.3 does not validate and escape the "order" and "orderby" GET parameters before using them in a SQL statement when viewing logs, leading to SQL injections issues

PLUGIN Log Email

CVE-2021-24774

HIGH CVSS 7.2 2021-10-25
Scroll to top