Known vulnerabilities in Email Address Encoder
A lightweight plugin that protects email addresses from email-harvesting robots, by encoding them into decimal and hexadecimal entities.
3Reported vulnerabilities
7.2Highest CVSS score
1.0.25Latest version
100,000+Active installs
What to do now
Update Email Address Encoder to 1.0.25 or later.
3 of these have a fixed version available. Updating resolves them.
Reported vulnerabilities
| CVE | Severity | Exploit probability |
Affected versions | Fixed in | Published |
|---|---|---|---|---|---|
| CVE-2026-5305 | High | 0.5% | Before 1.0.25 | 1.0.25 |
June 4, 2026 |
| CVE-2023-48765 | Medium | 0.4% | 1.0.22 to 1.0.22 (inclusive) | 1.0.23 |
November 28, 2023 |
| CVE-2024-43927 | Medium | 0.2% | 1.0.23 and earlier | 1.0.24 |
August 26, 2024 |