CVE-2016-10033

The mailSend function in the isMail transport in PHPMailer before 5.2.18 might allow remote attackers to pass extra parameters to the mail command...

Basic Information

CVE State
PUBLISHED
Reserved Date
December 22, 2016
Published Date
December 30, 2016
Last Updated
July 30, 2025
Vendor
PHPMailer
Product
PHPMailer
Description
The mailSend function in the isMail transport in PHPMailer before 5.2.18 might allow remote attackers to pass extra parameters to the mail command and consequently execute arbitrary code via a \" (backslash double quote) in a crafted Sender property.
Tags
php cisa nuclei_scanner

CVSS Scores

CVSS v3.1

9.8 - CRITICAL

Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

CVSS v2.0

7.5

Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

EPSS Score

Score
94.45% (Percentile: 99.99%) as of 2025-07-29

SSVC Information

Exploitation
active
Automatable
Yes
Technical Impact
total

Exploit Status

Exploited in the Wild
Yes (2025-07-07 17:45:39 UTC) Source

Known Exploited Vulnerability Information

Source Added Date
CISA 2025-07-07 17:45:30 UTC

Potential Proof of Concepts

Warning: These PoCs have not been tested and could contain malware. Use at your own risk.

wp_phpmailer_host_header

Type: metasploit • Created: Unknown

Metasploit module for CVE-2016-10033

sealldeveloper/CVE-2016-10033-PoC

Type: github • Created: 2025-04-25 15:47:14 UTC • Stars: 0

A PoC of CVE-2016-10033 I made for PentesterLab

Astrowmist/POC-CVE-2016-10033

Type: github • Created: 2024-05-22 05:33:58 UTC • Stars: 0

Proof Of Concept for the CVE-2016-10033 (PHPMailer)

zeeshanbhattined/exploit-CVE-2016-10033

Type: github • Created: 2022-08-05 08:24:14 UTC • Stars: 0

PHPMailer < 5.2.18 Remote Code Execution

j4k0m/CVE-2016-10033

Type: github • Created: 2021-08-31 13:46:28 UTC • Stars: 1

Remote Code Execution vulnerability in PHPMailer.

0x00-0x00/CVE-2016-10033

Type: github • Created: 2018-02-09 14:53:51 UTC • Stars: 7

PHPMailer < 5.2.18 Remote Code Execution Exploit

liusec/WP-CVE-2016-10033

Type: github • Created: 2017-07-22 03:20:41 UTC • Stars: 0

Bajunan/CVE-2016-10033

Type: github • Created: 2017-05-19 12:52:21 UTC • Stars: 0

WordPress 4.6 - Remote Code Execution (RCE) PoC Exploit

chipironcin/CVE-2016-10033

Type: github • Created: 2017-05-10 12:01:07 UTC • Stars: 2

Code and vulnerable WordPress container for exploiting CVE-2016-10033

GeneralTesler/CVE-2016-10033

Type: github • Created: 2017-05-10 03:18:46 UTC • Stars: 9

RCE against WordPress 4.6; Python port of https://exploitbox.io/vuln/WordPress-Exploit-4-6-RCE-CODE-EXEC-CVE-2016-10033.html

opsxcq/exploit-CVE-2016-10033

Type: github • Created: 2016-12-26 13:39:03 UTC • Stars: 403

PHPMailer < 5.2.18 Remote Code Execution exploit and vulnerable container

Timeline

  • CVE ID Reserved

  • CVE Published to Public

  • Detected by Nuclei

  • Detected by Metasploit

  • Added to KEVIntel