CVE-2025-49028: WordPress Zoho ZeptoMail plugin <= 3.3.1 - Cross Site Request Forgery (CSRF) to Stored XSS vulnerability
Cross-Site Request Forgery (CSRF) vulnerability in Zoho Mail Zoho ZeptoMail allows Stored XSS.This issue affects Zoho ZeptoMail: from n/a through 3.3.1.
Other sources
Cross-Site Request Forgery (CSRF) vulnerability in Zoho Mail Zoho ZeptoMail transmail allows Stored XSS.This issue affects Zoho ZeptoMail: from n/a through <= 3.3.1.
— MITRE
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-49028?
CVE-2025-49028 is classified as a moderate severity vulnerability due to its potential for Cross-Site Request Forgery leading to Stored XSS.
How do I fix CVE-2025-49028?
To fix CVE-2025-49028, update Zoho ZeptoMail to version 3.3.2 or later.
Which versions of Zoho ZeptoMail are affected by CVE-2025-49028?
CVE-2025-49028 affects Zoho ZeptoMail versions from n/a through 3.3.1.
Does CVE-2025-49028 affect any other software?
Yes, CVE-2025-49028 also affects the WordPress Zoho ZeptoMail plugin up to version 3.3.1.
What type of vulnerability is CVE-2025-49028?
CVE-2025-49028 is a Cross-Site Request Forgery (CSRF) vulnerability that can lead to Stored XSS.