CVE-2016-10033: PHPMailer Command Injection Vulnerability
Critical severity, CVSS 9.8. Actively exploited: in CISA KEV since 2025-07-07. EPSS: 99.7% chance of exploitation in the next 30 days.
The mailSend function in the isMail transport in PHPMailer before 5.2.18 might allow remote attackers to pass extra parameters to the mail command and consequently execute arbitrary code via a \" (backslash double quote) in a crafted Sender property.
Affected products
- Joomla! Joomla!: from 1.5.0, up to and including 3.6.5
- PHPMailer Project PHPMailer: before 5.2.18 (fixed in 5.2.18)
- WordPress WordPress: up to and including 4.7
Published 2016-12-30. Last modified 2026-06-17.