CVE-2026-5305: Unknown Email-Encoder-Premium

High severity, CVSS 8.8. EPSS: 0.5% chance of exploitation in the next 30 days.

The Email Address Encoder WordPress plugin before 1.0.25, email-encoder-premium WordPress plugin before 0.3.12 does not properly handle email replacement, which could allow unauthenticated users to perform Stored XSS attacks

Affected products

  • Unknown Email-Encoder-Premium: before 0.3.12 (fixed in 0.3.12)
  • Unknown Email Address Encoder: before 1.0.25 (fixed in 1.0.25)

Published 2026-06-25. Last modified 2026-06-25.