Medium 4.3 Unfixed
2025-09-05≤ 2.8.6
WordPress WP Email Template plugin <= 2.8.5 - Cross Site Request Forgery (CSRF) vulnerability
Minimum safe version
2.6.3
Update to 2.6.3 or later to address 4 fixable vulnerabilities
WordPress WP Email Template plugin <= 2.8.5 - Cross Site Request Forgery (CSRF) vulnerability
WP Email Template < 2.2.11 - HTML Injection
CVE-2019-25144
WP HTML Mail < 2.2.11 - HTML injection
a3 Lazy Load <= 2.6.0 - Cross-Site Request Forgery to Settings Reset