CVE-2025-60041
8.8Iulia Cazan · Emails Catch All
The Emails Catch All plugin for WordPress contains an authentication bypass vulnerability, allowing authenticated users to perform unauthorized password recovery.
Executive summary
A critical authentication bypass vulnerability in the Iulia Cazan Emails Catch All plugin allows authenticated attackers to compromise account security via unauthorized password recovery.
Vulnerability
The vulnerability is classified as an authentication bypass using an alternate path or channel, specifically affecting the password recovery mechanism. It requires the attacker to have at least low-level authenticated access to trigger the flaw.
Business impact
The ability for an attacker to bypass authentication mechanisms during the password recovery process poses a severe risk to user account integrity. Successful exploitation could lead to unauthorized account takeovers, potentially granting attackers full administrative control over the WordPress instance. Given the CVSS score of 8.8, this vulnerability represents a high risk to business operations and data confidentiality.
Remediation
Immediate Action: Monitor the vendor advisory for the release of a security patch and apply it immediately upon availability. If a patch is not yet available, consider disabling the plugin until a secure version is released.
Proactive Monitoring: Review web server and WordPress authentication logs for unusual password recovery requests or patterns indicating unauthorized account access attempts.
Compensating Controls: Deploy a Web Application Firewall (WAF) to filter malicious requests targeting the plugin's authentication endpoints.
Exploitation status
Public Exploit Available: Unknown
Analyst recommendation
The high severity of this vulnerability necessitates immediate attention from security administrators. Organizations utilizing the Emails Catch All plugin should prioritize the identification and mitigation of this flaw, ensuring that all plugins are updated as soon as the vendor provides a remediation path.
Sources
Originally found and disclosed by Denver Jackson | Patchstack Bug Bounty Program, per the CVE Program record.