Email Encoder – Protect Email Addresses and Phone Numbers, CVE-2021-24599
- CVE, Research URL
- Published on
- Sep 06, 2021
- Research Description
- The Email Encoder – Protect Email Addresses WordPress plugin before 2.1.2 has an endpoint that requires no authentication and will render a user supplied value in the HTML response without escaping or sanitizing the data.
- Affected versions
-
max 1.4.2.
- Status
-
vulnerable