WP Reroute Email Project maintains a narrow WordPress plugin focused on mail-handling functionality, with observed vulnerabilities centered on application-layer input and request-handling issues including cross-site scripting, SQL injection, and cross-site request forgery. Current exploitation activity and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Wp Reroute Email Project over time
Signals from CVEs in this vendor scope (3 CVEs).
3 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2023-27605CRITICAL Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Sajjad Hossain WP Reroute Email allows SQL Injection.This issue affects WP Rer | Nov 6, 2023 | 9.8 | 28 | NO | NO |
CVE-2023-27606HIGH Cross-Site Request Forgery (CSRF) vulnerability in Sajjad Hossain WP Reroute Email plugin <= 1.4.6 versions. | Jul 17, 2023 | 8.8 | 24 | NO | NO |
CVE-2023-3168MEDIUM The WP Reroute Email plugin for WordPress is vulnerable to Stored Cross-Site Scripting via an email subject in versions up to, and including, 1.4.9 due to insufficient input saniti | Jul 12, 2023 | 6.1 | 19 | NO | NO |
Signals from CVEs in this vendor scope (3 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Wp Reroute Email Project.
Media articles that mention a CVE ID that affects a product developed by Wp Reroute Email Project — matched by CVE ID, not by vendor name.