← WordPress Vulnerabilities
WordPress security by component

catalogx

catalogx is a WordPress plugin with 1 published CVE record in this archive. The latest tracked vulnerability was published Sep 02, 2026; the highest published CVSS base score is 4.3.

Plugin slug: catalogx

CVE-2026-79621: CatalogX permits unauthenticated stored email-content injection

CatalogX before 6.1.3 stores unauthenticated visitor content without adequate sanitization or escaping and later places it in the product-enquiry notification sent to the site administrator. The malicious content is delivered when an unrelated visitor submits a later enquiry.

PublishedSep 02, 2026
Known safe version6.1.3
Published vulnerabilities for catalogx
Safe version
Sep 02, 2026 CVE-2026-79621
CatalogX permits unauthenticated stored email-content injection
CatalogX before 6.1.3 stores unauthenticated visitor content without adequate sanitization or escaping and later places it in the product-enquiry notification sent to the site administrator. The malicious content is delivered when an unrelated visitor submits a later enquiry.
6.1.3
CVE4.3
NVDPending