The MM-email2image WordPress plugin through 0.2.5 does not have CSRF check in some places, and is missing sanitisation as well as escaping, which could allow attackers to make logged in admin add Stored XSS payloads via a CSRF attack
History

Tue, 10 Jun 2025 15:30:00 +0000

Type Values Removed Values Added
First Time appeared Mmilan81
Mmilan81 mm-email2image
Weaknesses CWE-352
CPEs cpe:2.3:a:mmilan81:mm-email2image:*:*:*:*:*:*:*:*
Vendors & Products Mmilan81
Mmilan81 mm-email2image

Wed, 20 Nov 2024 18:15:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 3.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:L/A:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


cve-icon MITRE

Status: PUBLISHED

Assigner: WPScan

Published: 2024-04-26T13:23:08.383Z

Updated: 2024-11-20T17:27:07.555Z

Reserved: 2024-03-29T01:03:12.464Z

Link: CVE-2024-3076

cve-icon Vulnrichment

Updated: 2024-08-01T19:32:42.564Z

cve-icon NVD

Status : Analyzed

Published: 2024-04-26T14:15:07.370

Modified: 2025-06-10T15:05:59.980

Link: CVE-2024-3076

cve-icon Redhat

No data.