This issue affects Zoho ZeptoMail: from n/a through 3.2.9.
Project Subscriptions
No advisories yet.
Solution
Update the WordPress Zoho ZeptoMail Plugin to the latest available version (at least 3.3.0).
Workaround
No workaround given by the vendor.
Thu, 21 May 2026 09:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-79 | |
| References |
|
Thu, 21 May 2026 09:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in fox-themes Prague prague-plugins allows Reflected XSS.This issue affects Prague: from n/a through <= 2.2.8. | Missing Authorization vulnerability in Zoho Mail Zoho ZeptoMail allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Zoho ZeptoMail: from n/a through 3.2.9. |
| Title | WordPress Prague plugin <= 2.2.8 - Cross Site Scripting (XSS) vulnerability | WordPress Zoho ZeptoMail plugin <= 3.2.9 - Broken Access Control vulnerability |
| Weaknesses | CWE-862 | |
| References |
| |
| Metrics |
cvssV3_1
|
cvssV3_1
|
Mon, 23 Feb 2026 22:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
cvssV3_1
|
Mon, 23 Feb 2026 15:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Fox-themes
Fox-themes prague Wordpress Wordpress wordpress |
|
| Vendors & Products |
Fox-themes
Fox-themes prague Wordpress Wordpress wordpress |
Fri, 20 Feb 2026 16:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in fox-themes Prague prague-plugins allows Reflected XSS.This issue affects Prague: from n/a through <= 2.2.8. | |
| Title | WordPress Prague plugin <= 2.2.8 - Cross Site Scripting (XSS) vulnerability | |
| Weaknesses | CWE-79 | |
| References |
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: Patchstack
Published:
Updated: 2026-05-21T08:26:38.169Z
Reserved: 2025-12-15T10:00:28.856Z
Link: CVE-2025-67972
Updated: 2026-02-23T21:46:49.632Z
Status : Deferred
Published: 2026-02-20T16:22:03.430
Modified: 2026-05-21T09:16:26.320
Link: CVE-2025-67972
No data.
OpenCVE Enrichment
Updated: 2026-05-21T11:00:11Z