Executive brief
The Email Address Encoder plugin for WordPress, which is designed to protect email addresses from being harvested by bots, contains a security flaw in how it processes email replacements. This vulnerability allows unauthenticated attackers to inject malicious scripts into a website. If successful, an attacker could hijack administrative sessions, deface the site, or redirect visitors to malicious websites.
Technical details
A Stored Cross-Site Scripting (XSS) vulnerability exists in the Email Address Encoder (Free < 1.0.25) and Premium (< 0.3.12) WordPress plugins. The issue stems from improper handling and sanitization during the email replacement process. An unauthenticated remote attacker can exploit this by submitting malicious payloads that are stored on the server and subsequently executed in the context of other users' browsers, including administrators. This can lead to full site compromise via session theft or unauthorized administrative actions. The vulnerability is addressed in versions 1.0.25 (Free) and 0.3.12 (Premium).
Affected products
- Unknown Email Address Encoder < 1.0.25
- Unknown email-encoder-premium < 0.3.12
Timeline
- 2026-06-04: disclosed
- 2026-06-25: advisory: NVD publication date