Medium 4.3
2025-12-31< 3.12.6
Email Capture <= 3.12.5 - Cross-Site Request Forgery
Minimum safe version
3.12.6
Update to 3.12.6 or later to address 7 fixable vulnerabilities
Email Capture <= 3.12.5 - Cross-Site Request Forgery
CVE-2025-67578
CVE-2023-28421
WordPress Email Marketing Plugin – WP Email Capture <= 3.10 - Missing Authorization to Email Capture List Download
CVE-2023-23723
CVE-2023-23724
WP Email Capture <= 3.9.3 - Authenticated (Administrator+) Stored Cross-Site Scripting