The MM-email2image WordPress plugin through 0.2.5 does not have CSRF check in some places, and is missing sanitisation as well as escaping, which could allow attackers to make logged in admin add Stored XSS payloads via a CSRF attack
Metrics
Affected Vendors & Products
References
History
Tue, 15 Jul 2025 13:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
epss
|
epss
|
Tue, 10 Jun 2025 15:30:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Mmilan81
Mmilan81 mm-email2image |
|
Weaknesses | CWE-352 | |
CPEs | cpe:2.3:a:mmilan81:mm-email2image:*:*:*:*:*:*:*:* | |
Vendors & Products |
Mmilan81
Mmilan81 mm-email2image |
Wed, 20 Nov 2024 18:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
cvssV3_1
|

Status: PUBLISHED
Assigner: WPScan
Published:
Updated: 2024-11-20T17:27:07.555Z
Reserved: 2024-03-29T01:03:12.464Z
Link: CVE-2024-3076

Updated: 2024-08-01T19:32:42.564Z

Status : Analyzed
Published: 2024-04-26T14:15:07.370
Modified: 2025-06-10T15:05:59.980
Link: CVE-2024-3076

No data.