CVE-2023-5672: Wpvibes Wp Mail Log
Medium severity, CVSS 6.5. EPSS: 0.7% chance of exploitation in the next 30 days.
The WP Mail Log WordPress plugin before 1.1.3 does not properly validate file path parameters when attaching files to emails, leading to local file inclusion, and allowing an attacker to leak the contents of arbitrary files.
Affected products
- Wpvibes Wp Mail Log: before 1.1.3 (fixed in 1.1.3)
Published 2023-12-26. Last modified 2026-06-17.