CVE-2026-1661: WP Mail Logging < 1.17.0 - Unauthenticated HTML Injection
The WP Mail Logging WordPress plugin before 1.17.0 does not properly restrict the HTML and CSS of logged emails before rendering them in its admin log screens, allowing unauthenticated users to inject styled content and links, for example through a public contact form, that can deceive an administrator viewing the log and send their browser to an attacker-controlled page.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
WP Mail Logging WordPress pluginto a version that resolves this vulnerability.Fixed in 1.17.0
Event History
Frequently Asked Questions
Who is exposed to this issue?
Sites using WP Mail Logging versions before 1.17.0 are exposed when they log emails that can be influenced by unauthenticated users, such as messages submitted through a public contact form. The immediate target is an administrator who opens the affected email entry in the plugin's admin log screens.
What does an attacker need to exploit it?
An attacker does not need authentication, but needs a way to cause attacker-controlled HTML or CSS to be included in an email that WP Mail Logging records. Exploitation also requires an administrator to view the logged email and interact with the deceptive rendered content, such as a link.
Is a default installation affected?
The issue affects versions before 1.17.0, but exploitation depends on the site logging emails containing attacker-controlled content. A public form or other unauthenticated email input path can provide that content.