The MM-email2image WordPress plugin through 0.2.5 does not have CSRF check in some places, and is missing sanitisation as well as escaping, which could allow attackers to make logged in admin add Stored XSS payloads via a CSRF attack
Metrics
Affected Vendors & Products
References
History
Tue, 10 Jun 2025 15:30:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Mmilan81
Mmilan81 mm-email2image |
|
Weaknesses | CWE-352 | |
CPEs | cpe:2.3:a:mmilan81:mm-email2image:*:*:*:*:*:*:*:* | |
Vendors & Products |
Mmilan81
Mmilan81 mm-email2image |
Wed, 20 Nov 2024 18:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
cvssV3_1
|

Status: PUBLISHED
Assigner: WPScan
Published: 2024-04-26T13:23:08.383Z
Updated: 2024-11-20T17:27:07.555Z
Reserved: 2024-03-29T01:03:12.464Z
Link: CVE-2024-3076

Updated: 2024-08-01T19:32:42.564Z

Status : Analyzed
Published: 2024-04-26T14:15:07.370
Modified: 2025-06-10T15:05:59.980
Link: CVE-2024-3076

No data.