WordPress security by component
catalogx
catalogx is a WordPress plugin with 1 published CVE record in this archive. The latest tracked vulnerability was published Sep 02, 2026; the highest published CVSS base score is 4.3.
Plugin slug:
catalogxLatest vulnerability
CVE-2026-79621: CatalogX permits unauthenticated stored email-content injection
CatalogX before 6.1.3 stores unauthenticated visitor content without adequate sanitization or escaping and later places it in the product-enquiry notification sent to the site administrator. The malicious content is delivered when an unrelated visitor submits a later enquiry.
| Safe version |
|
||
|---|---|---|---|
| Sep 02, 2026 |
CVE-2026-79621
CatalogX permits unauthenticated stored email-content injection
CatalogX before 6.1.3 stores unauthenticated visitor content without adequate sanitization or escaping and later places it in the product-enquiry notification sent to the site administrator. The malicious content is delivered when an unrelated visitor submits a later enquiry.
|
6.1.3 |
CVE4.3
NVDPending
|