CVE-2012-2579

WP SimpleMail 1.0.6 - Cross-Site Scripting via Email Fields

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2012-2579. PoCs published by loneferret.

AI-analyzed exploit summary This exploit demonstrates a stored XSS vulnerability in WP SimpleMail 1.0.6 by injecting malicious JavaScript payloads into email fields (To, From, Date, Subject). The PoC sends an email with an XSS payload via SMTP, exploiting insufficient input sanitization.

Description

Multiple cross-site scripting (XSS) vulnerabilities in the WP SimpleMail plugin 1.0.6 for WordPress allow remote attackers to inject arbitrary web script or HTML via the (1) To, (2) From, (3) Date, or (4) Subject field of an email.

Exploits (1)

exploitdb WORKING POC VERIFIED
by loneferret · pythonwebappsphp
https://www.exploit-db.com/exploits/20361

This exploit demonstrates a stored XSS vulnerability in WP SimpleMail 1.0.6 by injecting malicious JavaScript payloads into email fields (To, From, Date, Subject). The PoC sends an email with an XSS payload via SMTP, exploiting insufficient input sanitization.

Classification
Working Poc 95%
Attack Type
Xss
Complexity
Trivial
Reliability
Reliable
Target: WP SimpleMail 1.0.6 (WordPress Plugin)
Auth required
Prerequisites: SMTP server access · Valid credentials for SMTP authentication · WP SimpleMail plugin installed and configured
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (5)

Core 5
Core References
Exploit vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/54905
Third Party Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/50208
Third Party Advisory, VDB Entry vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/77538
Exploit exploit x_refsource_exploit-db
http://www.exploit-db.com/exploits/20361
Third Party Advisory, VDB Entry vdb-entry x_refsource_osvdb
http://osvdb.org/84534

Scores

EPSS 0.0375
EPSS Percentile 88.5%

Details

CWE
CWE-79
Status published
Products (1)
wp_simplemail_project/wp_simplemail 1.0.6
Published Jun 20, 2014
Tracked Since Feb 18, 2026