CVE Details
Basic Information
| Title |
CVE-2025-1123 Solid Mail – SMTP email and logging made by SolidWP <= 2.1.5 - Unauthenticated Stored Cross-Site Scripting via Email |
| Type |
cve |
| Published |
2025-05-23T12:22:55 |
| Last Seen |
2025-05-23T13:15:31 |
CVSS Information
| Base Score |
7.2 (HIGH) |
| Attack Vector |
NETWORK |
| Attack Complexity |
LOW |
| Privileges Required |
NONE |
| User Interaction |
NONE |
| Scope |
CHANGED |
| Confidentiality Impact |
LOW |
| Integrity Impact |
LOW |
| Availability Impact |
NONE |
AI Analysis
| AI Description |
The Solid Mail plugin for WordPress is vulnerable to stored cross-site scripting (XSS) in all versions up to and including 2.1.5. This vulnerability allows unauthenticated attackers to inject malicious scripts into emails, which can be executed when viewed by administrators or other users. |
| AI Severity |
High |
| Vendor |
SolidWP |
| Product |
Solid Mail – SMTP email and logging |
| Affected Version |
<= 2.1.5 |
Additional Information
| CVE List |
CVE-2025-1123 |
| CWE List |
CWE-79 |
| Bulletin Family |
cve |
Description
The Solid Mail – SMTP email and logging made by SolidWP plugin for WordPress is vulnerable to Stored Cross-Site Scripting via email Name, Subject, and Body in all versions up to, and including, 2.1.5…
CVSS Score Summary
Base Score: %!f(string=#) (HIGH)
View Full CVE Details