What this page helps you verify fast
This hub clusters every indexed record for Email Template Designer – WP HTML Mail so operators can confirm whether a disclosed issue maps to the installed slug, version range, and patch path.
Review known vulnerability records for the WordPress plugin Email Template Designer – WP HTML Mail (`wp-html-mail`), including severity, CVE references, affected versions, and patch status.
Recent tracked CVEs on this page include CVE-2023-40202, CVE-2022-0218 and CVE-2021-20779, so operators can jump from disclosure to patch validation without scanning the full feed first.
Start with the highest-signal CVE records for this WordPress plugin before scanning the full vulnerability feed.
WordPress Email Template Designer < 3.0.8 - Cross-Site Request Forgery
WP HTML Mail <= 3.0.9 - Missing Authorization on Rest Route
WP HTML Mail < 2.9.1 - HTML Injection
WP HTML Mail <= 3.4.0 - Cross-Site Request Forgery via 'send_test'
This hub clusters every indexed record for Email Template Designer – WP HTML Mail so operators can confirm whether a disclosed issue maps to the installed slug, version range, and patch path.
These recent records surface the CVE strings, patch cues, and direct report links most operators need first.
The WP HTML Mail plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 3.4.0. This is due to missing or incorrect nonce validation on the 'send_t...
The WP HTML Mail WordPress plugin is vulnerable to unauthorized access which allows unauthenticated attackers to retrieve and modify theme settings due to a missing capability check on the /...
Cross-site request forgery (CSRF) vulnerability in WordPress Email Template Designer - WP HTML Mail versions prior to 3.0.8 allows remote attackers to hijack the authentication of administra...
Sorted by latest disclosure date so newly published issues surface first.
The WP HTML Mail plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 3.4.0. This is due to missing or incorrect nonce validation on the 'send_test' function. This makes it possible for unauthenticated attackers to send test emails vi...
The WP HTML Mail WordPress plugin is vulnerable to unauthorized access which allows unauthenticated attackers to retrieve and modify theme settings due to a missing capability check on the /themesettings REST-API endpoint found in the ~/includes/class-template-designer.php file,...
Cross-site request forgery (CSRF) vulnerability in WordPress Email Template Designer - WP HTML Mail versions prior to 3.0.8 allows remote attackers to hijack the authentication of administrators via unspecified vectors.
The WP HTML Mail plugin for WordPress is vulnerable to HTML injection in versions up to, and including, 2.9.0.3 due to insufficient input sanitization. This makes it possible for unauthenticated attackers to inject arbitrary HTML in pages that execute if they can successfully tri...