{"dataType":"CVE_RECORD","dataVersion":"5.2","cveMetadata":{"cveId":"CVE-2019-25150","assignerOrgId":"b15e7b5b-3da4-40ae-a43c-f7aa60e62599","state":"PUBLISHED","assignerShortName":"Wordfence","dateReserved":"2023-06-06T13:41:19.179Z","datePublished":"2023-06-07T01:51:53.028Z","dateUpdated":"2026-04-08T17:33:23.801Z"},"containers":{"cna":{"providerMetadata":{"orgId":"b15e7b5b-3da4-40ae-a43c-f7aa60e62599","shortName":"Wordfence","dateUpdated":"2026-04-08T17:33:23.801Z"},"affected":[{"vendor":"saadiqbal","product":"Email Templates Customizer and Designer for WordPress and WooCommerce","versions":[{"version":"0","status":"affected","lessThanOrEqual":"1.3","versionType":"semver"}],"defaultStatus":"unaffected"}],"descriptions":[{"lang":"en","value":"The Email Templates plugin for WordPress is vulnerable to HTML Injection in versions up to, and including, 1.3. This makes it possible for attackers to present phishing forms or conduct cross-site request forgery attacks against site administrators."}],"title":"Email Templates <= 1.3 - HTML Injection","references":[{"url":"https://www.wordfence.com/threat-intel/vulnerabilities/id/f5c449f1-4715-4033-b0a3-6a8ca968aabc?source=cve"},{"url":"https://blog.nintechnet.com/multiple-wordpress-plugins-vulnerable-to-html-injection/"},{"url":"https://wordpress.org/plugins/email-templates/#developers"}],"problemTypes":[{"descriptions":[{"lang":"en","description":"CWE-74 Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')","cweId":"CWE-74","type":"CWE"}]}],"metrics":[{"cvssV3_1":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","baseScore":8.8,"baseSeverity":"HIGH"}}],"credits":[{"lang":"en","type":"finder","value":"Jerome Bruandet"}],"timeline":[{"time":"2019-10-25T00:00:00.000Z","lang":"en","value":"Disclosed"}]},"adp":[{"providerMetadata":{"orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE","dateUpdated":"2024-08-05T03:00:19.263Z"},"title":"CVE Program Container","references":[{"url":"https://www.wordfence.com/threat-intel/vulnerabilities/id/f5c449f1-4715-4033-b0a3-6a8ca968aabc?source=cve","tags":["x_transferred"]},{"url":"https://blog.nintechnet.com/multiple-wordpress-plugins-vulnerable-to-html-injection/","tags":["x_transferred"]},{"url":"https://wordpress.org/plugins/email-templates/#developers","tags":["x_transferred"]}]},{"metrics":[{"other":{"type":"ssvc","content":{"timestamp":"2024-12-23T16:00:43.850417Z","id":"CVE-2019-25150","options":[{"Exploitation":"none"},{"Automatable":"no"},{"Technical Impact":"total"}],"role":"CISA Coordinator","version":"2.0.3"}}}],"title":"CISA ADP Vulnrichment","providerMetadata":{"orgId":"134c704f-9b21-4f2e-91b3-4a467353bcc0","shortName":"CISA-ADP","dateUpdated":"2024-12-23T16:20:46.099Z"}}]}}