CVE-2016-10033 is a critical remote code execution vulnerability in PHPMailer versions prior to 5.2.18, affecting various products including Joomla and WordPress. This flaw allows remote attackers to inject extra parameters into the mail command via a crafted Sender property, leading to arbitrary code execution. With a CVSS score of 9.8 and an EPSS score indicating high exploitability, this vulnerability poses a severe risk. It is actively exploited in the wild, with multiple public exploits, Metasploit modules, and Nuclei templates available, and has garnered significant community discussion and media attention.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 5.2.18CPE matchmatch criteria | cpe:2.3:a:phpmailer_project:phpmailer:*:*:*:*:*:*:*:* | ||
<= 4.7CPE matchmatch criteria | cpe:2.3:a:wordpress:wordpress:*:*:*:*:*:*:*:* | ||
>= 1.5.0, <= 3.6.5CPE matchmatch criteria | cpe:2.3:a:joomla:joomla\!:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.