DriversRecommendedOutdated drivers can make a good PC feel brokenScan driver issues before chasing fixes manually.Scan NowOctober DealsAmazon USOctober deal check: compare before you payAmazon US: current deals, useful picks and tech finds.Check DealsClean PCRecommendedOne scan can reveal what keeps slowing WindowsLook for cleanup and repair opportunities.Run Scan×
Skip to content
CVE-2016-10033

CVE-2016-10033: PHPMailer Remote-Code-Execution Vulnerability and Fix

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

CVE-2016-10033 is a critical remote-code-execution flaw in PHPMailer’s native isMail transport. PHPMailer 5.2.17 and earlier are vulnerable when attacker-controlled sender data reaches PHP’s mail() command path. Version 5.2.18 fixed this CVE, but the related CVE-2016-10045 made 5.2.20 the safer historical minimum. The practical recommendation today is to move to a supported PHPMailer 6.x or 7.x release, verify which copy is actually loaded, and investigate reachable vulnerable systems for signs of compromise.

At a glance

Item Detail
CVE CVE-2016-10033
Component PHPMailer’s isMail/mailSend path
Impact Remote command injection leading to arbitrary code execution
Affected upstream versions PHPMailer 5.2.17 and earlier
Original fix 5.2.18, released December 24, 2016
Safer historical 5.2 baseline 5.2.20, which also fixed CVE-2016-10045
Severity CVSS 3.1 9.8 Critical (AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)
Weakness CWE-88, improper neutralization of command-argument delimiters
Current action Upgrade to a supported PHPMailer branch and confirm the runtime transport

NVD records CVE-2016-10033 in CISA’s Known Exploited Vulnerabilities catalog. CISA added it on July 7, 2025, with a July 28, 2025 remediation date; NVD’s associated assessment lists exploitation as active, automatable, and capable of total technical impact. Those designations prioritize remediation but do not prove that every installation has been compromised. NVD vulnerability record

What CVE-2016-10033 does

PHPMailer is a PHP library used to construct and send email. In vulnerable releases, the isMail transport passes sender-related data toward PHP’s native mail() function without safely neutralizing command delimiters. If an attacker can control a sender value, specially crafted quoting or shell metacharacters can inject additional arguments into the mail command. Under suitable PHP and operating-system conditions, that becomes arbitrary command execution as the web-server or PHP process account.

This is more serious than email spoofing or header injection: successful exploitation can affect confidentiality, integrity, and availability. NVD describes the issue as allowing remote attackers to pass extra parameters to the mail command through a crafted Sender property. NVD technical description

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
#1 Best Overall

Which PHPMailer versions are affected?

Version Status
5.2.17 and earlier Vulnerable to CVE-2016-10033
5.2.18 Original fix for CVE-2016-10033
5.2.19 Not a sufficient final destination because CVE-2016-10045 remained relevant
5.2.20 and later in 5.2 Includes the related CVE-2016-10045 fix
Supported 6.x or 7.x Preferred path, subject to the application’s PHP requirements

The PHPMailer changelog dates 5.2.18 to December 24, 2016, and 5.2.20 to December 28, 2016. Version 5.2.25, released August 28, 2017, was the final official 5.2 release, but the project no longer supports that branch for security updates and recommends migration to newer major versions. The project repository showed a 7.1.1 release dated May 18, 2026; select the newest release compatible with your PHP and application stack rather than treating that number as a universal requirement. PHPMailer changelog · PHPMailer repository

Why CVE-2016-10045 matters

CVE Main issue Historical fixed version
CVE-2016-10033 Argument injection through vulnerable isMail handling 5.2.18
CVE-2016-10045 Related incomplete-fix or bypass vulnerability in the same general area 5.2.20

CVE-2016-10045 exists because the original fix was incomplete. Therefore, “upgrade to 5.2.18” is accurate only for CVE-2016-10033 itself, not as a complete historical hardening recommendation. CVE-2016-10045 record

When is a site actually remotely exposed?

Having a PHPMailer directory on disk does not automatically make a site exploitable. The relevant conditions are all of the following:

  • The vulnerable PHPMailer copy is the one loaded at runtime.
  • The application invokes the isMail transport rather than only SMTP or another sender.
  • An internet-reachable mail function exists, such as a contact, registration, password-reset, feedback, or mail-test endpoint.
  • Attacker-controlled input reaches From, Sender, or an equivalent envelope-sender value.
  • The PHP and operating-system environment permits the resulting command execution to have useful effect.

A system may contain old code yet avoid this path because it uses SMTP, keeps sender values fixed, or leaves the library unused. Conversely, a current CMS can still be exposed if a plugin, extension, vendor bundle, or manually copied library carries an old PHPMailer version.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Joomla, WordPress, and bundled copies

NVD lists PHPMailer through 5.2.17, Joomla 1.5.0 through 3.6.5, and WordPress through 4.7 in affected-configuration data. These ranges are not a verdict that every installation in them has the same remotely exploitable path. Bundled library versions, extensions, transport configuration, input validation, and endpoint reachability determine exposure. NVD affected configurations

Joomla specifically warns that extensions which bundle their own PHPMailer copy, or which bypass Joomla’s mail API, require independent checking. Updating the core application alone may not replace those copies. Joomla security advisory

Check the deployed dependency

Composer-managed installations

composer show phpmailer/phpmailer
composer why phpmailer/phpmailer
composer audit

Use the installed version, dependency path, and composer.lock as evidence. composer.json alone may describe a range rather than the package actually deployed. Audit output depends on the Composer version and configured package sources.

Manually bundled or CMS copies

find /var/www -iname '*phpmailer*' 2>/dev/null
grep -R "VERSION|VERSION_MAJOR|VERSION_MINOR" /var/www 2>/dev/null | grep -i phpmailer

Search vendor directories, extensions, plugins, uploads, and custom application trees. Multiple copies can coexist; determine which one the runtime autoloader selects.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Confirm the transport and data flow

grep -RniE 'isMail|mailSend|Mailer[[:space:]]*=|PHPMailer|mail[[:space:]]*(' /var/www 2>/dev/null

Search results show possible reachability, not proof of exploitation. Confirm configuration and runtime behavior in a controlled staging environment. Look for native mail() selection, dynamic transport settings, and user values assigned to sender fields.

Remediation plan

  1. Inventory every copy. Include Composer packages, CMS extensions, vendor directories, and custom bundles.
  2. Update the parent application or extension. Use its official update mechanism where it manages dependencies.
  3. Move to a supported PHPMailer branch. Respect the application’s PHP and framework constraints, then regenerate and deploy the lock file as appropriate.
  4. Remove duplicate or shadowed copies. Verify that the intended version is loaded at runtime.
  5. Test mail workflows. Exercise contact forms, password resets, queue workers, attachments, internationalized addresses, and delivery failures.
  6. Use SMTP only as a compensating control when necessary. Secure authentication, TLS certificate validation, outbound rules, rate limits, and sender semantics still require configuration.

Sending through SMTP can avoid the vulnerable native-mail() path; an advisory for CVE-2016-10045 lists SMTP to localhost as a workaround. It does not remove the need to patch PHPMailer or eliminate other mail-related risks. Related advisory

Do not blindly replace files in a CMS-managed installation. A later application update may overwrite the change or expect a vendor-specific patch.

Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

Incident-response checks

If a vulnerable, reachable system existed, treat confirmed exploitation as possible host compromise rather than merely email abuse. Preserve evidence before logs rotate and review:

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
  • Web access logs for suspicious requests to contact, registration, password-reset, and mail-test endpoints.
  • PHP and application error logs, including abnormal mail-command failures.
  • Unexpected child processes launched by the web-server account.
  • New or modified PHP files in web roots, upload, cache, and temporary directories.
  • Cron jobs, systemd timers, SSH keys, shell history, and other persistence.
  • Outbound network connections and unusual mail-delivery patterns.
  • Credential use from the affected host after the suspected exploitation window.

Record file hashes and modification times. Rotate credentials from a trusted system when compromise is plausible, and rebuild from known-good images when integrity cannot be established. Public exploit material and a CISA KEV listing establish risk and exploitation relevance, not compromise of every installation.

Why a WAF is not the fix

WAF or IPS signatures can help block known requests, and Check Point documented IPS protection for this vulnerability, but network controls are defense in depth. They do not correct vulnerable code, protect internal endpoints, or remediate a host that was already compromised. Check Point advisory

Final checklist

  • Identify the actual PHPMailer version loaded in production.
  • Find every bundled or extension-owned copy.
  • Confirm whether isMail is reachable and whether sender data is user-controlled.
  • Upgrade to a supported PHPMailer release; do not stop at 5.2.18.
  • Test all mail workflows and verify the runtime dependency after deployment.
  • Use secured SMTP only as a temporary compensating measure when appropriate.
  • Review logs, files, processes, outbound traffic, and credentials if exposure was possible.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

Leave a Reply

Your email address will not be published. Required fields are marked *

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Read next

Recommended PC Tool
Recommended PC Tool
Windows Errors? Fix Them Before They SpreadFree repair scan
Outdated Drivers Are Slowing You DownFree scan - exact matches

Two free Windows tools

One Free Minute Could Fix That PC

Before you go - each of these free tools takes about a minute and tackles what quietly slows a Windows PC down.

Special offer. View Outbyte info, uninstall instructions, EULA, and Privacy Policy.