CYBERSECURITY BRIEFING NOTE OVERVIEW CVE-2026-2840 affects the Email Encoder – Protect Email Addresses and Phone Numbers WordPress plugin in all versions up to 2.4.4. The vulnerability is a Stored Cross-Site Scripting (XSS) flaw in the 'eeb_mailto' shortcode caused by insufficient input sanitization and output escaping. Authenticated contributors and higher-privileged users can inject malicious scripts into page content that executes for all subsequent visitors. SEVERITY The vulnerability carries a CVSS score of 6.4 (Medium) with network accessibility, low attack complexity, and low privilege requirements. While the attack requires authenticated access, it affects the confidentiality and integrity of site content with cross-site scope impact. The attack vector is network-based and requires no user interaction from the attacker, though victims must visit affected pages for payload execution. The FAUCET Risk Score of 35.0/100 indicates moderate exploitability potential. EXPLOITATION STATUS There is no evidence of active exploitation in the wild. The vulnerability is not listed on the CISA Known Exploited Vulnerabilities (KEV) catalog, and its presence on inactive lists suggests minimal community or threat actor attention. The exceptionally low EPSS score of 0.0003 indicates this vulnerability ranks lower than over 99.9 percent of CVEs in current exploitation likelihood, suggesting limited practical risk in typical environments at this time.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
| Onlineoptimisation | Email Encoder – Protect Email Addresses And Phone Numbers | >= 0, <= 2.4.4CNA affecteddefault unaffected |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.