Back

CVE-2016-10045

CRITICAL

The isMail transport in PHPMailer before 5.2.20 might allow remote attackers to pass extra parameters to the mail command and consequently execute arbitrary code by leveraging improper interaction between the escapeshellarg function and internal escaping performed in the mail function in PHP. NOTE: this vulnerability exists because of an incorrect fix for CVE-2016-10033.

Published: Dec 30, 2016 Modified: Jun 17, 2026
CWE-77

CVSS Metrics

CVSSv3
Attack Vector: NETWORK Attack Complexity: LOW Privileges Required: NONE User Interaction: NONE Scope: UNCHANGED Confidentiality Impact: HIGH Integrity Impact: HIGH Availability Impact: HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Affected Products (3)

Vendor Product Version
phpmailer_project phpmailer * < 5.2.20
wordpress wordpress *
joomla joomla\! * ≥ 1.5.0

GitHub Security Advisory GHSA-4pc3-96mx-wwc8

Remote code execution in PHPMailer

composer phpmailer/phpmailer >= 5.0.0, < 5.2.20 Fixed: 5.2.20

Risk Scores

CVSS Score 9.8 / 10
EPSS Score 98.04%

Top 0% most likely to be exploited

Threat Score 78.6 / 100

Data Sources

NVD EPSS GitHub