CVE-2026-5305 Details
Description
The Email Address Encoder WordPress plugin before 1.0.25, email-encoder-premium WordPress plugin before 0.3.12 does not properly handle email replacement, which could allow unauthenticated users to perform Stored XSS attacks
A stored cross-site scripting vulnerability has been identified in the Email Address Encoder WordPress plugin, affecting versions prior to 1.0.25, and the email-encoder-premium WordPress plugin, prior to version 0.3.12. The issue arises because the plugins do not properly manage email replacement, which could enable unauthenticated users to execute stored XSS attacks.
Users of the free Email Address Encoder WordPress plugin should update to version 1.0.25 or later. Users of the email-encoder-premium WordPress plugin should update to version 0.3.12 or later.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Jun 25, 2026CISA-ADP
Assessed Jun 25, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://wpscan.com/vulnerability/bf59610b-98ba-4c05-b2fc-85c163e9a389/ | [email protected] | AdvisoryExploitRemedy |
Weakness Enumeration
No weakness enumeration is available for this CVE.
Affected Products
| Product | Versions |
|---|---|
| Email Address Encoder | < 1.0.25 (semver) |
CPE
Remediation
| |
| Email Address Encoder Premium | < 0.3.12 (semver) |
CPE
Remediation
| |
Change History
2 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 25, 2026 | CVE Modified | CISA-ADP |
| Jun 25, 2026 | New CVE Received | [email protected] |
Volerion