CVE-2025-22303: WordPress WP Mailster plugin <= 1.8.17.0 - Sensitive Data Exposure vulnerability
Published Jan 7, 2025
·Updated
Insertion of Sensitive Information Into Sent Data vulnerability in brandtoss WP Mailster wp-mailster allows Retrieve Embedded Sensitive Data.This issue affects WP Mailster: from n/a through <= 1.8.17.0.
Affected Software
3 affected components
Wpmailster Wp Mailster Wordpress<1.8.18
brandtoss WP Mailster<=1.8.17.0
WordPress WP Mailster<=1.8.17.0
Remediation
Information
Update the WordPress WP Mailster wordpress plugin to the latest available version (at least 1.8.18.0).
Event History
Jan 7, 2025
CVE Published
via MITRE·10:48 AM
Data Sourced
via MITRE·10:48 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·11:15 AM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2025-22303?
CVE-2025-22303 is classified as a medium severity vulnerability.
2
How do I fix CVE-2025-22303?
To fix CVE-2025-22303, update WP Mailster to version 1.8.18 or higher.
3
What are the risks associated with CVE-2025-22303?
CVE-2025-22303 can lead to the exposure of sensitive information embedded in sent data.
4
Which versions of WP Mailster are affected by CVE-2025-22303?
CVE-2025-22303 affects WP Mailster versions up to and including 1.8.17.0.
5
Can CVE-2025-22303 impact user privacy?
Yes, CVE-2025-22303 can significantly impact user privacy by leaking sensitive data.