Jamesward's vulnerability footprint centers on its WP Mail Catcher WordPress plugin, with the observed exposure driven by application-layer input-handling weaknesses including cross-site scripting and SQL injection. Current severity, exploitation status, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Jamesward over time
Signals from CVEs in this vendor scope (3 CVEs).
3 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2023-50844HIGH Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in James Ward Mail logging – WP Mail Catcher.This issue affects Mail logging – WP | Dec 28, 2023 | 7.2 | 20 | NO | NO |
CVE-2023-3080MEDIUM The WP Mail Catcher plugin for WordPress is vulnerable to Stored Cross-Site Scripting via an email subject in versions up to, and including, 2.1.2 due to insufficient input sanitiz | Jul 12, 2023 | 6.1 | 20 | NO | NO |
CVE-2024-32099MEDIUM Cross-Site Request Forgery (CSRF) vulnerability in James Ward WP Mail Catcher.This issue affects WP Mail Catcher: from n/a through 2.1.6. | Apr 15, 2024 | 4.3 | 15 | NO | NO |
Signals from CVEs in this vendor scope (3 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Jamesward.
Media articles that mention a CVE ID that affects a product developed by Jamesward — matched by CVE ID, not by vendor name.