← Back

Onlineoptimisation

onlineoptimisation

3 CVEs • 1 product

Products (1)

Click to collapse
Toggle
Email Encoder
email_encoder

CVEs (3)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
2Jannisthuemmig
Onlineoptimisation
2Email Encoder
Email Encoder
Jul 22, 2026
Feb 29, 2024
N/A· v4
5.4 MEDIUM· v3
N/A· v2
The Email Encoder – Protect Email Addresses and Phone Numbers plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcode(s) in all versions up to, and including, 2.2.0 due to insufficien...Show more
The Email Encoder – Protect Email Addresses and Phone Numbers plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcode(s) in all versions up to, and including, 2.2.0 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers with contributor-level and above permissions to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.Show less
2Jannisthuemmig
Onlineoptimisation
2Email Encoder
Email Encoder
Jul 22, 2026
Jan 11, 2024
N/A· v4
5.4 MEDIUM· v3
N/A· v2
The Email Encoder – Protect Email Addresses and Phone Numbers plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's eeb_mailto shortcode in all versions up to, and including, 2.1.9 due to ins...Show more
The Email Encoder – Protect Email Addresses and Phone Numbers plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's eeb_mailto shortcode in all versions up to, and including, 2.1.9 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers with contributor-level and above permissions to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.Show less
2Jannisthuemmig
Onlineoptimisation
2Email Encoder
Email Encoder
Jul 22, 2026
Nov 22, 2023
N/A· v4
5.4 MEDIUM· v3
N/A· v2
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Jannis Thuemmig Email Encoder plugin <= 2.1.8 versions.