Emails Catch <= 3.5.3 - Authenticated (Subscriber+) Information Exposure to Password Reset and Privilege Escalation

2025-10-11 00:00
Denver Jackson

Strategic Overview

Status
Patched in 3.5.4
Affected PluginEmails Catch All
Affected Version<= 3.5.3
CVSS8.8High
CVECVE-2025-60041
View all Emails Catch All vulnerabilities

Vulnerability Overview

The Emails Catch All plugin for WordPress is vulnerable to privilege escalation via email log exposure in all versions up to, and including, 3.5.3. This is due to the plugin not properly restricting access to email logs. This makes it possible for authenticated attackers, with Subscriber-level access and above, to trigger a password reset email that gets logged for all users, including administrators, and leverage that to reset the user's password and gain access to their account.

Technical Analysis

REMEDIATION: Update to version 3.5.4, or a newer patched version --- IDENTIFIER: CWE-200 (Exposure of Sensitive Information to an Unauthorized Actor) The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.

External References

Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C

Emails Catch <= 3.5.3 - Authenticated (Subscriber+) Information Exposure to Password Reset and Privilege Escalation (CVE-2025-60041)