Known CVE
WordPress PHPMailer < 5.2.18 - Remote Code Execution
WordPress PHPMailer before 5.2.18 might allow remote attackers to pass extra parameters to the mail command and consequently execute arbitrary code via a " (backslash double quote) in a crafted Sender property in isMail transport.
CVE-2016-10033
Critical2016CVSS 9.8CWE-88
cve2016 · seclists · rce · edb · wordpress · phpmailer_project · kev · vkev
Verified scans run this check after you prove you own the site.
All known CVEsView the checks catalogNational Vulnerability Database
Scan a website