CVE-2023-51410 CRITICAL

CVE-2023-51410: WordPress WP Mail Log Plugin <= 1.1.2 is vulnerable to Arbitrary File Upload

Vendor Wpvibes
Product WP Mail Log
Weakness CWE-434 · Unrestricted file upload
Published December 29, 2023
Last update April 28, 2026

CVSS base score

9.9/10
Attack vector Network
Attack complexity Low
Privileges required Low
User interaction None
Confidentiality High
Integrity High

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H

What the vulnerability does

01Description

Unrestricted Upload of File with Dangerous Type vulnerability in WPVibes WP Mail Log.This issue affects WP Mail Log: from n/a through 1.1.2.

Explanation of Vulnerability in Simple Terms

02Summary

WP Mail Log versions up to 1.1.2 do not properly validate file uploads, allowing authenticated users with low privileges to upload arbitrary files to the server. An attacker can upload malicious files such as PHP scripts to execute code, modify site content, or compromise the entire WordPress installation. This vulnerability affects all users of the plugin and requires immediate patching.

What an attacker can do

03Attacker Capabilities

Upload and execute arbitrary files on the server, including PHP code, to take control of the site.

Potential impact on your site

04Site Impact

Complete site compromise possible; attacker can run code, steal data, modify content, or lock you out.

Conditions required to exploit

05Prerequisites

Attacker must have a low-privilege WordPress user account (e.g., subscriber or contributor role).

Key dates

06Disclosure timeline

December 29, 2023 CVE published
April 28, 2026 Record updated

Related vulnerabilities

08Related CVE