PHPMailer 6.1.8 through 6.4.0 allows object injection through Phar Deserialization via addAttachment with a UNC pathname. NOTE: this is similar to CVE-2018-19296, but arose because 6.1.8 fixed a functionality problem in which UNC pathnames were always considered unreadable by PHPMailer, even in safe contexts. As an unintended side effect, this fix eliminated the code that blocked addAttachment exploitation.
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HPhpmailer Project Phpmailer
APPPhpmailer Project6.1.8 – 6.4.0WordPress
APPWordpress3.7 – 3.7.36 (excl.)3.8 – 3.8.36 (excl.)3.9 – 3.9.34 (excl.)4.0 – 4.0.33 (excl.)4.1 – 4.1.33 (excl.)4.2 – 4.2.30 (excl.)4.3 – 4.3.26 (excl.)4.4 – 4.4.25 (excl.)4.5 – 4.5.24 (excl.)4.6 – 4.6.21 (excl.)4.7 – 4.7.21 (excl.)4.8 – 4.8.17 (excl.)4.9 – 4.9.18 (excl.)5.0 – 5.0.13 (excl.)5.1 – 5.1.10 (excl.)+ 6 more
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
Tags
Deserialization
CWE
References
Related vulnerabilities
CVE-2026-63030CRITICAL9.8⚠ KEVPL ✓same product
WordPress: RCE przez route confusion w REST API i SQL Injection
CVE-2016-10033CRITICAL9.8⚠ KEVPL ✓same product
PHPMailer — RCE poprzez argument injection w funkcji mailSend
CVE-2020-28035CRITICAL9.8PL ✓same product
Privilege escalation w WordPress przez XML-RPC (przed wersją 5.5.2)
CVE-2020-28032CRITICAL9.8PL ✓same product
WordPress — niebezpieczna deserializacja w FilteredIterator
CVE-2020-28036CRITICAL9.8PL ✓same product
WordPress: privilege escalation przez XML-RPC przy komentowaniu wpisów