CVE-2019-25150

HIGH

Email Templates <1.3 - Code Injection

Title source: llm
STIX 2.1

Description

The Email Templates plugin for WordPress is vulnerable to HTML Injection in versions up to, and including, 1.3. This makes it possible for attackers to present phishing forms or conduct cross-site request forgery attacks against site administrators.

Scores

CVSS v3 8.8
EPSS 0.0120
EPSS Percentile 64.4%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact total

Details

CWE
CWE-74
Status published
Products (2)
saadiqbal/Email Templates Customizer and Designer for WordPress and WooCommerce < 1.3
wpexperts/email_templates < 1.3.1
Published Jun 07, 2023
Tracked Since Feb 18, 2026