DevSecOps Toolkit

CVE record

CVE-2026-5776

MEDIUMCVSS 6.1

The Email Encoder WordPress plugin before 2.4.7 does not escape email addresses retrieved via user input, allowing unauthenticated attackers to perform Stored XSS attacks

Vulnerability metadata

Published
2026-05-20T01:46:15.903Z
Modified
2026-05-20T08:31:24.027Z
EPSS
Not available
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

References