Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Fri, 26 Jun 2026 10:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Email Encoder
Email Encoder email Encoder Simple Mail Address Encoder Project Simple Mail Address Encoder Project simple Mail Address Encoder Wordpress Wordpress wordpress |
|
| Vendors & Products |
Email Encoder
Email Encoder email Encoder Simple Mail Address Encoder Project Simple Mail Address Encoder Project simple Mail Address Encoder Wordpress Wordpress wordpress |
Thu, 25 Jun 2026 17:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-79 |
Thu, 25 Jun 2026 15:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-79 |
Thu, 25 Jun 2026 13:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
cvssV3_1
|
Thu, 25 Jun 2026 07:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-79 |
Thu, 25 Jun 2026 06:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | The Email Address Encoder WordPress plugin before 1.0.25, email-encoder-premium WordPress plugin before 0.3.12 does not properly handle email replacement, which could allow unauthenticated users to perform Stored XSS attacks | |
| Title | Email Address Encoder (Free < 1.0.25, Premium < 0.3.12) - Unauthenticated Stored XSS | |
| References |
|
Status: PUBLISHED
Assigner: WPScan
Published:
Updated: 2026-06-25T12:39:14.030Z
Reserved: 2026-04-01T08:24:23.721Z
Link: CVE-2026-5305
Updated: 2026-06-25T12:38:02.736Z
No data.
No data.
OpenCVE Enrichment
Updated: 2026-06-26T09:38:30Z