Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2026-2840

22
FAUCET Score

CYBERSECURITY BRIEFING NOTE OVERVIEW CVE-2026-2840 affects the Email Encoder – Protect Email Addresses and Phone Numbers WordPress plugin in all versions up to 2.4.4. The vulnerability is a Stored Cross-Site Scripting (XSS) flaw in the 'eeb_mailto' shortcode caused by insufficient input sanitization and output escaping. Authenticated contributors and higher-privileged users can inject malicious scripts into page content that executes for all subsequent visitors. SEVERITY The vulnerability carries a CVSS score of 6.4 (Medium) with network accessibility, low attack complexity, and low privilege requirements. While the attack requires authenticated access, it affects the confidentiality and integrity of site content with cross-site scope impact. The attack vector is network-based and requires no user interaction from the attacker, though victims must visit affected pages for payload execution. The FAUCET Risk Score of 35.0/100 indicates moderate exploitability potential. EXPLOITATION STATUS There is no evidence of active exploitation in the wild. The vulnerability is not listed on the CISA Known Exploited Vulnerabilities (KEV) catalog, and its presence on inactive lists suggests minimal community or threat actor attention. The exceptionally low EPSS score of 0.0003 indicates this vulnerability ranks lower than over 99.9 percent of CVEs in current exploitation likelihood, suggesting limited practical risk in typical environments at this time.

Impacted Technologies

VendorProductVersion(s)CPE
OnlineoptimisationEmail Encoder – Protect Email Addresses And Phone Numbers
>= 0, <= 2.4.4CNA affecteddefault unaffected

CVSS Data

CVSS version used by this source: 3.1

6.4MEDIUM

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N

Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
LOW
User Interaction
NONE
Scope
CHANGED
Confidentiality Impact
LOW
Integrity Impact
LOW
Availability Impact
NONE
Exploitability Score
3.1
Impact Score
2.7
CvssVersion
3.1

Exploit Intelligence

EPSS Score
0.26%
Probability of exploitation in next 30 days
EPSS Percentile
17.3%
Percentile rank of EPSS score among Peer Group
As of 2026-07-27
Model: v2026.06.15
This CVE's current EPSS score of 0.0026 is in the 21st percentile among its peer group of 21,977 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Remediation records are not available for this CVE.

References

plugins.trac.wordpress.org / changeset
plugins.trac.wordpress.org / changeset
wordfence.com / threat-intel/vulnerabilities/id/9987b5b4-33d8-4446-acbe-58c6cb5604df