S4E just found a high-severity finding from ssl sweet32 vulnerability checker
PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
medium·Product Based Web Vulnerabilities·Updated Jan 3, 2024

CVE-2022-0218 Scanner

Detects 'Cross-Site Scripting (XSS)' vulnerability in WP HTML Mail plugin for WordPress affects v. 3.0.9 and before.

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsurl
CostFree
2k
Times Used
continuous scan runs
4.7k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
CVECVE-2022-0218
6.1
CVSShigh
Exploitable remotely over the internet · no authentication required.

The WP HTML Mail WordPress plugin is vulnerable to unauthorized access which allows unauthenticated attackers to retrieve and modify theme settings due to a missing capability check on the /themesettings REST-API endpoint found in the ~/includes/class-template-designer.php file, in versions up to and including 3.0.9. This makes it possible for attackers with no privileges to execute the endpoint and add malicious JavaScript to a vulnerable WordPress site.

Attack Vector
Network
Privileges Req.
None
User Interaction
None
Affected
WP HTML Mailby codemiq
3.0.9
Updated Aug 22, 2026View on NVD →
Detail

The WP HTML Mail plugin for WordPress is a popular email customization plugin that allows website owners to send professional and customizable emails to their subscribers. This plugin is widely used because it makes email design and management a breeze. With WP HTML Mail, users can easily build their own email templates and customize the look and feel of their emails. They can also include dynamic content, such as post updates, in their emails without hassle.

However, security researchers have recently discovered a severe flaw in the plugin's codebase. The vulnerability identified as CVE-2022-0218, allows attackers to gain unauthorized access to sensitive information. Specifically, this vulnerability allows unauthenticated attackers to retrieve and modify theme settings using the /themesettings REST-API endpoint found in the ~/includes/class-template-designer.php file. This flaw allows a malicious actor to execute the endpoint and inject malicious JavaScript into a vulnerable WordPress site.

If this vulnerability is exploited, it opens a pandora's box of potential risks and dangers. With the ability to modify theme settings, an attacker can easily modify the website's appearance, redirect traffic to malicious sites, and even steal user data. This vulnerability can also be used to exploit other plugins or extensions installed on the website.

At S4E, we offer advanced services to help you learn about and protect your digital assets. Our platform features pro-level security scanning that detects and alerts you about any vulnerabilities or threats on your website. With our services, you can rest assured that your website is always safe and secure. Protect your online presence today by signing up for S4E.

 

REFERENCES

Solution Advice

It's essential to take immediate precautionary measures to protect your website from this vulnerability. Here are some things you can do to mitigate the risk:

  • Update WP HTML Mail to the latest version.
  • Use a security plugin like Sucuri or Wordfence to regularly scan your website for vulnerabilities.
  • Only install plugins and extensions from reliable sources and keep them up to date.
  • Disable any unused plugins and extensions.
  • Implement a web application firewall to protect against attacks.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.