CVE-2016-10045 is a critical remote code execution vulnerability affecting PHPMailer versions prior to 5.2.20, including its integration within Joomla and WordPress. This flaw, an incorrect fix for CVE-2016-10033, allows attackers to inject extra parameters into the mail command due to improper interaction between escapeshellarg and PHP's internal mail function. With a CVSS score of 9.8 (CRITICAL), it presents a low-complexity attack vector with no user interaction required, leading to complete compromise of confidentiality, integrity, and availability. The vulnerability has publicly available exploit modules in Metasploit and ExploitDB, indicating a high potential for exploitation, and has garnered significant community discussion and media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 5.2.20CPE matchmatch criteria | cpe:2.3:a:phpmailer_project:phpmailer:*:*:*:*:*:*:*:* | ||
<= 4.7CPE matchmatch criteria | cpe:2.3:a:wordpress:wordpress:*:*:*:*:*:*:*:* | ||
>= 1.5.0, <= 3.6.5CPE matchmatch criteria | cpe:2.3:a:joomla:joomla\!:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.