CVE 8.8 HIGH

WordPress Emails Catch All plugin <= 3.5.3 - Broken Authentication vulnerability_CVE-2025-60041

8.8 / 10
HIGH
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:C/C:H/I:L/A:L

Description

Authentication Bypass Using an Alternate Path or Channel vulnerability in Iulia Cazan Emails Catch All emails-catch-all allows Password Recovery Exploitation.This issue affects Emails Catch All: from n/a through <= 3.5.3.

AI Analysis

Broken Authentication vulnerability in Emails Catch All plugin

Basic Information

ID CVE-2025-60041
Source Patchstack
Published Oct 22, 2025 at 14:32
Modified Oct 23, 2025 at 13:28

Affected Product

Vendor Iulia Cazan
Product Emails Catch All
Version n/a
Affected Versions Iulia Cazan Emails Catch All n/a

CWE Classification

AI Assessment

AI Score 8.8 / 10
AI Severity High
Vendor Iulia Cazan
Product Emails Catch All
Version <= 3.5.3

References

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.