CVE-2026-79621
Received Received - Intake

Unauthenticated Email Content Injection in CatalogX WordPress Plugin

Vulnerability report for CVE-2026-79621, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-02

Last updated on: 2026-09-02

Assigner: WPScan

Description

The CatalogX WordPress plugin before 6.1.3 does not sanitise or escape content that an unauthenticated user can store before including it in the product enquiry notification email sent to the site administrator, allowing unauthenticated attackers to inject arbitrary content into that email, which is delivered when an unrelated visitor later submits a product enquiry.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-02
Last Modified
2026-09-02
Generated
2026-09-02
AI Q&A
2026-09-02
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 2 associated CPEs
Vendor Product Version / Range
catalogx catalogx to 6.1.3 (exc)
catalogx wordpress_plugin to 6.1.3 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-UNKNOWN

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

The CatalogX WordPress plugin before version 6.1.3 has a flaw where it does not properly sanitize or escape user input stored in a shared transient. An unauthenticated attacker can inject arbitrary content into the product enquiry notification email sent to the site administrator. This malicious content is then delivered when an unrelated visitor submits a product enquiry.

Detection Guidance

Check if the CatalogX WordPress plugin version is below 6.1.3. Look for unauthorized content in product enquiry notification emails sent to administrators. Review server logs for suspicious transient data storage or email generation triggered by unrelated visitor submissions.

Impact Analysis

This vulnerability allows attackers to send unauthorized or malicious content to the site administrator via email. It could lead to phishing attempts, spreading malware, or disrupting normal site operations. The impact depends on how the administrator interacts with the injected content.

Compliance Impact

This vulnerability could potentially affect compliance with GDPR and HIPAA by allowing unauthorized data injection into emails sent to site administrators. If sensitive personal or health data is included in these emails, improper handling or exposure could violate GDPR's data protection requirements or HIPAA's privacy rules.

Mitigation Strategies

Update the CatalogX plugin to version 6.1.3 or later immediately. If updating is not possible, consider disabling the plugin temporarily until a patch is applied. Monitor administrator email content for unexpected or malicious payloads.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-79621. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart