The MM-email2image WordPress plugin through 0.2.5 does not have CSRF check in some places, and is missing sanitisation as well as escaping, which could allow attackers to make logged in admin add Stored XSS payloads via a CSRF attack
Metrics
Affected Vendors & Products
References
History
Tue, 15 Jul 2025 13:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
epss
|
epss
|
Tue, 10 Jun 2025 15:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Mmilan81
Mmilan81 mm-email2image |
|
| Weaknesses | CWE-352 | |
| CPEs | cpe:2.3:a:mmilan81:mm-email2image:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Mmilan81
Mmilan81 mm-email2image |
Wed, 20 Nov 2024 18:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: WPScan
Published:
Updated: 2024-11-20T17:27:07.555Z
Reserved: 2024-03-29T01:03:12.464Z
Link: CVE-2024-3076
Updated: 2024-08-01T19:32:42.564Z
Status : Analyzed
Published: 2024-04-26T14:15:07.370
Modified: 2025-06-10T15:05:59.980
Link: CVE-2024-3076
No data.