Executive brief
The Email Encoder plugin for WordPress, which is used to protect email addresses from being harvested by bots, contains a security vulnerability. This flaw allows high-privileged users, such as site administrators, to inject malicious scripts into the website's settings. These scripts could then execute in the browsers of other users, potentially leading to unauthorized actions or data theft, even in restricted environments like WordPress Multisite.
Technical details
The Email Encoder plugin for WordPress fails to properly sanitize and escape input in its settings, specifically within the 'WP_Email_Encoder_Bundle_options[protection_text]' parameter. An attacker with high privileges (such as an Administrator) can inject a malicious payload that is stored in the database. This payload is subsequently executed in the context of a victim's browser when they visit pages or posts where the '[eeb_protect_content]' shortcode is embedded. This vulnerability is particularly relevant in WordPress Multisite environments where the 'unfiltered_html' capability is typically restricted for site admins. The issue is fixed in version 2.3.4.
Affected products
- WPScan Email Encoder < 2.3.4
Timeline
- 2026-03-30: disclosed: Publicly published by WPScan
- 2026-04-20: advisory: NVD published date