Report: CVE-2024-7083 - Email Encoder < 2.3.4 - Admin+ Stored XSS

Report: CVE-2024-7083 - Email Encoder < 2.3.4 - Admin+ Stored XSS

CVE ID :CVE-2024-7083 Published : April 20, 2026, 7:16 a.m. | 1 hour, 34 minutes ago Description :The Email Encoder WordPress plugin before 2.3.4 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup). Severity: 0.0 | NA Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVE Details

Severity
HIGH
Published
April 20, 2026
Affected Product: WordPress