CVE-2024-4483: Wp-Webhooks Email Encoder

Medium severity, CVSS 5.4. EPSS: 0.4% chance of exploitation in the next 30 days.

The Email Encoder WordPress plugin before 2.2.2 does not escape the WP_Email_Encoder_Bundle_options[protection_text] parameter before outputting it back in an attribute in an admin page, leading to a Stored Cross-Site Scripting

Affected products

  • Wp-Webhooks Email Encoder: before 2.2.2 (fixed in 2.2.2)

Published 2024-07-29. Last modified 2026-06-17.