ZeroHour
Security Affairspublished ()ingested @securityaffairs

CVE-2016-10033 PHPMailer flaw leaves millions of websites vulnerable

criticalVulnerabilityimportance 60CVE-2016-10033

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2016-10033
Command Injection RCE in PHPMailer (Ships with WordPress and Joomla)

CVE-2016-10033 is an argument/command injection flaw in the mailSend function of PHPMailer's isMail transport, affecting all PHPMailer releases before 5.2.18. When a crafted Sender (From) address containing a backslash-double-quote sequence is passed to the underlying mail command, extra arguments can be injected, allowing an unauthenticated remote attacker to execute arbitrary code on the hosting server. Because PHPMailer is one of the most widely distributed PHP mail libraries and is bundled with WordPress and Joomla, a very large population of sites and PHP applications is potentially affected, though exploitable deployments are those sending mail via the isMail transport with attacker-influenced sender addresses. CISA added the flaw to its Known Exploited Vulnerabilities catalog on 2025-07-07 and EPSS assigns a 99.7% probability of exploitation within 30 days, so active exploitation should be assumed. Ransomware association is currently listed as unknown.

Do: Upgrade PHPMailer to 5.2.18 or later everywhere it is deployed, including bundled copies inside WordPress, Joomla, and other PHP applications, and bring CMS cores current. Audit internet-facing forms, contact handlers, and API endpoints that pass user-supplied email addresses as the Sender/From value, and identify which systems send mail via the isMail transport. Federal agencies must apply vendor mitigations per CISA instructions or follow BOD 22-01 guidance for cloud services; treat exploitation as likely given the KEV listing and 99.7% EPSS.

9.8100% KEV PoC ×14
  • phpmailer project PHPMailer all versions before 5.2.18
  • WordPress
  • Joomla!
masshundreds of millions of sites potentially affected (PHPMailer is bundled with WordPress, which runs roughly 40% of all websites, plus millions of Joomla…
Full article317 words · extracted from securityaffairs.com · click to collapse

Pierluigi Paganini December 27, 2016

A security expert discovered a critical vulnerability in the PHPMailer that leaves millions of websites vulnerable to remote exploit.

A critical vulnerability, tracked as CVE-2016-10033, affects PHPMailer, one of the most popular open source PHP libraries used to send emails. It has been estimated that more than 9 Million users worldwide leverages on this library.

Millions of websites using PHP and popular CMS, including WordPress, Drupal, and Joomla currently use the library for sending emails.

The CVE-2016-10033 affects all versions of the library before the PHPMailer 5.2.18 release.

PHPMailer

The flaw was discovered by the notorious security expert Dawid Golunski from Legal Hackers, it could be exploited by a remote unauthenticated attacker to execute arbitrary code in the context of the web server and compromise the target web application.

“An independent research uncovered a critical vulnerability in PHPMailer that could potentially be used by (unauthenticated) remote attackers to achieve remote arbitrary code execution in the context of the web server user and remotely compromise the target web application.” Golunski explained in a security advisory.

“To exploit the vulnerability an attacker could target common website components such as contact/feedback forms, registration forms, password email resets and others that send out emails with the help of a vulnerable version of the PHPMailer class.” 

The advisory provides a few details about the exploitation of the flaw to give users a chance to fix their PHPMailer class. The experts confirmed that the details of the CVE-2016-10033 vulnerability will be published shortly.

Golunski reported the flaw to the developers who have promptly fixed it in the PHPMailer 5.2.18 release.
The researcher also plans to include in the advisory a proof-of-concept exploit code and video PoC of the attack.

Administrators and developers must update to the patched release as soon as possible.

Stay tuned

[adrotate banner=”9″]

Pierluigi Paganini

(Security Affairs – CVE-2016-10033, hacking)



Text extracted automatically; images, tables and formatting may be missing. Original: https://securityaffairs.com/54759/hacking/phpmailer-cve-2016-10033-flaw.html