Junglewise Threat Intelligence

CVE-2023-33999: WPVibes WP Mail Log DOM-based XSS in Freemius library

CVE-2023-33999 · Severity: high · CVSS 7.1 · Published 2026-06-11

Executive brief

WP Mail Log is a WordPress plugin used to track and log emails sent from a website. A security flaw in this plugin allows attackers to inject malicious scripts into the site, which could lead to unauthorized actions being performed in a user's browser, such as redirecting visitors to malicious websites or stealing session information. This occurs when a site administrator or visitor interacts with a specially crafted link or page.

Technical details

The WP Mail Log plugin for WordPress (versions 1.0.2 and below) is vulnerable to DOM-based Cross-Site Scripting (XSS) via the Freemius library (versions prior to 2.5.10). The vulnerability stems from improper neutralization of user-supplied input during web page generation, allowing an unauthenticated attacker to inject malicious scripts. Exploitation requires a victim (typically an administrator) to perform an action such as clicking a crafted link (User Interaction required). Successful exploitation can lead to arbitrary JavaScript execution in the context of the victim's browser session. The issue is resolved in version 1.1.1 of the plugin, which includes an updated version of the Freemius library.

Affected products

  • WPVibes WP Mail Log <= 1.0.2

Timeline

  • 2023-07-19: disclosed: Initial disclosure by Patchstack
  • 2023-07-19: advisory: Patchstack advisory published
  • 2026-06-11: advisory: NVD publication date

References