CVE-2026-79621
Last modified
CVE-2026-79621 is a medium-severity vulnerability rated 4.3/10 on the CVSS scale. The CatalogX WordPress plugin before 6.1.3 does not sanitise or escape content that an unauthenticated user can store before including it in the product enquiry notification email sent to the site administrator, allowing unauthenticated attackers to inject arbitrary content into that email, which is delivered when an unrelated visitor later submits a product enquiry.. EPSS estimates a 0.10% chance of exploitation in the next 30 days.
Description
The CatalogX WordPress plugin before 6.1.3 does not sanitise or escape content that an unauthenticated user can store before including it in the product enquiry notification email sent to the site administrator, allowing unauthenticated attackers to inject arbitrary content into that email, which is delivered when an unrelated visitor later submits a product enquiry.
Metrics
Weakness Enumeration
Affected Software
Source: CNA advisory (CVE.org). NVD analysis pending.
| Vendor | Product | Versions |
|---|---|---|
| Unknown | CatalogX | < 6.1.3 |
References
Timeline
- Published
- Last Modified
- Status
- Deferred
Frequently Asked Questions
What is CVE-2026-79621?
How severe is CVE-2026-79621?
How do I fix CVE-2026-79621?
How Strix Helps
- Same Subject, Wrong User: A Cross-Issuer Account Takeover in n8nStrix found an identity-binding bug in n8n's token-exchange flow enabling account takeover.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-7961Insufficient validation of untrusted input in Permissions in…4.3
- CVE-2026-79615The Quiz and Survey Master (QSM) WordPress plugin before 11…2.7
- CVE-2026-79616Out-of-bounds read while parsing untrusted SVG path strings …0.6
- CVE-2026-79617Incorrect Permission Assignment for Critical Resource vulner…7.1
- CVE-2026-79619On Linux, several OpenZFS ioctl authorization checks accept …7.3
- CVE-2026-7962Insufficient policy enforcement in DirectSockets in Google C…5.4
- CVE-2026-79622A weakness has been identified in dekdee adobe-xd-mcp 1.0.0.…7.3
- CVE-2026-79623A security vulnerability has been detected in FishCodeTech M…6.3
- CVE-2026-7963Inappropriate implementation in ServiceWorker in Google Chro…8.3
- CVE-2026-79630The WPFunnels WordPress plugin before 3.13.0 does not verif…5.3
- CVE-2026-79631The WPFunnels WordPress plugin before 3.13.0 does not restr…5.3
- CVE-2026-79632The WPFunnels WordPress plugin before 3.13.0 does not perfo…5.3
Are you affected by CVE-2026-79621?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
