Emailkit – email customizer for woocommerce & wp
This hub aggregates every CVE we track for Emailkit – email customizer for woocommerce & wp, a product in the web cms plugins space. Use it to gauge the current risk picture and drill into individual advisories.
4
CVEs tracked
0
Critical
0
High
0
In CISA KEV
Severity distribution
MEDIUM4
Monthly trend
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
1
1
1
0
1
0
0
0
0
2024-102026-09
Latest CVEs
The 4 most recently published vulnerabilities affecting Emailkit – email customizer for woocommerce & wp.
- CVE-2026-5957EmailKit <= 1.6.5 - Authenticated (Author+) Arbitrary File Read via 'emailkit-editor-template' REST Parameter6.5
- CVE-2026-3474EmailKit <= 1.6.3 - Authenticated (Administrator+) Path Traversal via 'emailkit-editor-template' REST API Parameter4.9
- CVE-2026-1925EmailKit – Email Customizer for WooCommerce & WP <= 1.6.2 - Missing Authorization to Authenticated (Subscriber+) Arbitrary Post Title Modification4.3
- CVE-2025-14059EmailKit <= 1.6.1 - Authenticated (Author+) Arbitrary File Read via Path Traversal6.5
Product normalization is registry-driven with AI assist and human review. How it works