Cross-Site Scripting
10 records100%First: 2015. Latest: 2026.
Plugin security history
The Wordfence Intelligence dataset currently contains 10 vulnerability records associated with Email Encoder – Protect Email Addresses and Phone Numbers, published between 2015 and 2026.
Dataset last synchronized: 2026-08-02 09:41:47 UTC
At a glance
| Year | Records | Relative volume |
|---|---|---|
| 2015 | 1 | |
| 2021 | 1 | |
| 2023 | 2 | |
| 2024 | 3 | |
| 2026 | 3 |
| Severity | Records | Share |
|---|---|---|
| High | 1 | 10% |
| Medium | 9 | 90% |
First: 2015. Latest: 2026.
Patch status reflects the latest successfully synchronized source dataset and must be checked against the installed version.
2.4.72.3.42.4.52.2.22.2.12.1.102.1.92.1.21.4.2Ranges are deduplicated by source range record and shown with the associated disclosure and known patched versions.
| Affected range | Vulnerability | Published | Patched version | Severity |
|---|---|---|---|---|
[*, 2.4.7) | Email Encoder – Protect Email Addresses and Phone Numbers < 2.4.7 - Unauthenticated Stored Cross-Site Scripting | June 11, 2026 | 2.4.7 | High |
[*, 2.3.4) | Email Encoder – Protect Email Addresses and Phone Numbers < 2.3.4 - Authenticated (Administrator+) Stored Cross-Site Scripting | April 21, 2026 | 2.3.4 | Medium |
*-2.4.4 | Email Encoder – Protect Email Addresses and Phone Numbers <= 2.4.4 - Authenticated (Contributor+) Stored Cross-Site Scripting via eeb_mailto Shortcode | April 15, 2026 | 2.4.5 | Medium |
*-2.2.1 | Email Encoder – Protect Email Addresses and Phone Numbers <= 2.2.1 - Authenticated (Admin+) Stored Cross-Site Scripting | July 8, 2024 | 2.2.2 | Medium |
*-2.2.0 | Email Encoder – Protect Email Addresses and Phone Numbers <= 2.2.0 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode | February 13, 2024 | 2.2.1 | Medium |
*-2.1.9 | Email Encoder – Protect Email Addresses and Phone Numbers <= 2.1.9 - Authenticated (Contributor+) Stored Cross-Site Scripting | January 9, 2024 | 2.1.10 | Medium |
*-2.1.8 | Email Encoder Bundle <= 2.1.8 - Authenticated (Contributor+) Stored Cross-Site Scripting via shortcode | November 15, 2023 | 2.1.9 | Medium |
*-2.1.8 | Email Encoder <= 2.1.8 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode | August 29, 2023 | 2.1.9 | Medium |
*-2.1.1 | Email Encoder <= 2.1.1 - Reflected Cross Site Scripting | August 2, 2021 | 2.1.2 | Medium |
[*, 1.4.2) | Email Encoder < 1.4.2 - Cross-Site Scripting | August 10, 2015 | 1.4.2 | Medium |
Selected source records
Published: June 11, 2026
Published: April 21, 2026
Published: April 15, 2026
Published: July 8, 2024
Published: February 13, 2024
Published: January 9, 2024
Published: November 15, 2023
Published: August 29, 2023
Published: June 11, 2026
Published: November 15, 2023
Published: February 13, 2024
Published: April 15, 2026
Published: August 29, 2023
Published: January 9, 2024
Published: August 10, 2015
Published: August 2, 2021
Running an affected version does not prove that a website was compromised. Suspicious redirects, unknown administrators, injected content, unexpected files or recurring malware may require a manual investigation.
Vulnerability data: Wordfence Intelligence. Analysis and practical guidance: 3Zero Digital.
This page aggregates active Production Feed records. Counts are not software-quality rankings, and an affected version does not prove exploitation or infection. Read the full methodology.