CVE-2026-1661
Received Received - Intake

WP Mail Logging Plugin HTML Injection Vulnerability

Vulnerability report for CVE-2026-1661, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-02

Last updated on: 2026-10-02

Assigner: WPScan

Description

The WP Mail Logging WordPress plugin before 1.17.0 does not properly restrict the HTML and CSS of logged emails before rendering them in its admin log screens, allowing unauthenticated users to inject styled content and links, for example through a public contact form, that can deceive an administrator viewing the log and send their browser to an attacker-controlled page.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-02
Last Modified
2026-10-02
Generated
2026-10-02
AI Q&A
2026-10-02
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
wp_mail_logging wp_mail_logging to 1.17.0 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-UNKNOWN

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability is an unauthenticated HTML injection flaw in the WP Mail Logging WordPress plugin before version 1.17.0. The plugin does not properly sanitize HTML and CSS content in logged emails before displaying them in the admin log interface. This allows attackers to inject malicious styled content or links that can deceive administrators viewing the logs.

Detection Guidance

Check if the WP Mail Logging plugin version is below 1.17.0 by inspecting the plugin files or WordPress admin panel. Look for unauthorized HTML or CSS content in email logs displayed in the admin interface.

Impact Analysis

An attacker could exploit a public contact form to inject malicious content into the logs. When an administrator views the logs, the injected content could trick them into visiting an attacker-controlled page, potentially leading to further compromise of the system or data.

Compliance Impact

This vulnerability could potentially impact compliance with GDPR and HIPAA by allowing unauthorized data exposure or manipulation. Attackers could inject malicious links or content into admin logs viewed through the plugin, potentially leading to phishing attacks or unauthorized access to sensitive information. This may violate data protection principles under GDPR and HIPAA's integrity and confidentiality requirements.

Mitigation Strategies

Update the WP Mail Logging plugin to version 1.17.0 or later immediately. If updating is not possible, consider disabling the plugin until an update is applied.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-1661. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart