Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Wed, 02 Sep 2026 13:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-20 CWE-79 |
Wed, 02 Sep 2026 11:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-345 | |
| Metrics |
cvssV3_1
|
Wed, 02 Sep 2026 08:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-20 CWE-79 |
Wed, 02 Sep 2026 06:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | The CatalogX WordPress plugin before 6.1.3 does not sanitise or escape content that an unauthenticated user can store before including it in the product enquiry notification email sent to the site administrator, allowing unauthenticated attackers to inject arbitrary content into that email, which is delivered when an unrelated visitor later submits a product enquiry. | |
| Title | CatalogX < 6.1.3 - Unauthenticated Email Content Injection via Shared Transient | |
| References |
|
Subscriptions
No data.
Status: PUBLISHED
Assigner: WPScan
Published:
Updated: 2026-09-02T10:45:56.333Z
Reserved: 2026-08-25T08:35:51.210Z
Link: CVE-2026-79621
Updated: 2026-09-02T10:11:50.954Z
Status : Received
Published: 2026-09-02T06:17:18.390
Modified: 2026-09-02T11:17:22.030
Link: CVE-2026-79621
No data.
OpenCVE Enrichment
Updated: 2026-09-02T13:30:05Z
-
CWE-345
Insufficient Verification of Data Authenticity