CVE-2019-25150 HIGH

CVE-2019-25150: Email Templates <= 1.3 - HTML Injection

Vendor Saadiqbal
Product Email Templates Customizer and Designer for WordPress and WooCommerce
Weakness CWE-74
Published June 7, 2023
Last update April 8, 2026

CVSS base score

8.8/10
Attack vector Network
Attack complexity Low
Privileges required None
User interaction Required
Confidentiality High
Integrity High

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

What the vulnerability does

01Description

The Email Templates plugin for WordPress is vulnerable to HTML Injection in versions up to, and including, 1.3. This makes it possible for attackers to present phishing forms or conduct cross-site request forgery attacks against site administrators.

Explanation of Vulnerability in Simple Terms

02Summary

The Email Templates Customizer and Designer plugin for WordPress and WooCommerce versions 1.3 and earlier contains an improper input validation flaw that allows attackers to inject and execute malicious code. An attacker can craft a malicious link or file that, when clicked or opened by a site administrator, executes arbitrary code with full site privileges. This affects all installations running the vulnerable versions.

What an attacker can do

03Attacker Capabilities

Execute arbitrary code on the WordPress site by tricking an admin into clicking a malicious link.

Potential impact on your site

04Site Impact

Attackers can take full control of your WordPress site, steal data, modify content, or install backdoors.

Conditions required to exploit

05Prerequisites

An administrator must click a link or visit a page controlled by the attacker.

Key dates

06Disclosure timeline

June 7, 2023 CVE published
April 8, 2026 Record updated

Related vulnerabilities

08Related CVE