CVE-2024-4483: Wp-Webhooks Email Encoder
Medium severity, CVSS 5.4. EPSS: 0.4% chance of exploitation in the next 30 days.
The Email Encoder WordPress plugin before 2.2.2 does not escape the WP_Email_Encoder_Bundle_options[protection_text] parameter before outputting it back in an attribute in an admin page, leading to a Stored Cross-Site Scripting
Affected products
- Wp-Webhooks Email Encoder: before 2.2.2 (fixed in 2.2.2)
Published 2024-07-29. Last modified 2026-06-17.