CVE-2016-10033 is a critical remote-code-execution flaw in PHPMailer’s native isMail transport. PHPMailer 5.2.17 and earlier are vulnerable when attacker-controlled sender data reaches PHP’s mail() command path. Version 5.2.18 fixed this CVE, but the related CVE-2016-10045 made 5.2.20 the safer historical minimum. The practical recommendation today is to move to a supported PHPMailer 6.x or 7.x release, verify which copy is actually loaded, and investigate reachable vulnerable systems for signs of compromise.
At a glance
| Item | Detail |
|---|---|
| CVE | CVE-2016-10033 |
| Component | PHPMailer’s isMail/mailSend path |
| Impact | Remote command injection leading to arbitrary code execution |
| Affected upstream versions | PHPMailer 5.2.17 and earlier |
| Original fix | 5.2.18, released December 24, 2016 |
| Safer historical 5.2 baseline | 5.2.20, which also fixed CVE-2016-10045 |
| Severity | CVSS 3.1 9.8 Critical (AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H) |
| Weakness | CWE-88, improper neutralization of command-argument delimiters |
| Current action | Upgrade to a supported PHPMailer branch and confirm the runtime transport |
NVD records CVE-2016-10033 in CISA’s Known Exploited Vulnerabilities catalog. CISA added it on July 7, 2025, with a July 28, 2025 remediation date; NVD’s associated assessment lists exploitation as active, automatable, and capable of total technical impact. Those designations prioritize remediation but do not prove that every installation has been compromised. NVD vulnerability record
What CVE-2016-10033 does
PHPMailer is a PHP library used to construct and send email. In vulnerable releases, the isMail transport passes sender-related data toward PHP’s native mail() function without safely neutralizing command delimiters. If an attacker can control a sender value, specially crafted quoting or shell metacharacters can inject additional arguments into the mail command. Under suitable PHP and operating-system conditions, that becomes arbitrary command execution as the web-server or PHP process account.
This is more serious than email spoofing or header injection: successful exploitation can affect confidentiality, integrity, and availability. NVD describes the issue as allowing remote attackers to pass extra parameters to the mail command through a crafted Sender property. NVD technical description
Do these 3 things before closing this tab:
1Clear out junk files and repair common Windows errors2Fix the driver behind crashes, sound loss and screen glitches3Repair Windows errors before they cause bigger problems#1 Best Overall
Which PHPMailer versions are affected?
| Version | Status |
|---|---|
| 5.2.17 and earlier | Vulnerable to CVE-2016-10033 |
| 5.2.18 | Original fix for CVE-2016-10033 |
| 5.2.19 | Not a sufficient final destination because CVE-2016-10045 remained relevant |
| 5.2.20 and later in 5.2 | Includes the related CVE-2016-10045 fix |
| Supported 6.x or 7.x | Preferred path, subject to the application’s PHP requirements |
The PHPMailer changelog dates 5.2.18 to December 24, 2016, and 5.2.20 to December 28, 2016. Version 5.2.25, released August 28, 2017, was the final official 5.2 release, but the project no longer supports that branch for security updates and recommends migration to newer major versions. The project repository showed a 7.1.1 release dated May 18, 2026; select the newest release compatible with your PHP and application stack rather than treating that number as a universal requirement. PHPMailer changelog · PHPMailer repository
Why CVE-2016-10045 matters
| CVE | Main issue | Historical fixed version |
|---|---|---|
| CVE-2016-10033 | Argument injection through vulnerable isMail handling |
5.2.18 |
| CVE-2016-10045 | Related incomplete-fix or bypass vulnerability in the same general area | 5.2.20 |
CVE-2016-10045 exists because the original fix was incomplete. Therefore, “upgrade to 5.2.18” is accurate only for CVE-2016-10033 itself, not as a complete historical hardening recommendation. CVE-2016-10045 record
When is a site actually remotely exposed?
Having a PHPMailer directory on disk does not automatically make a site exploitable. The relevant conditions are all of the following:
- The vulnerable PHPMailer copy is the one loaded at runtime.
- The application invokes the
isMailtransport rather than only SMTP or another sender. - An internet-reachable mail function exists, such as a contact, registration, password-reset, feedback, or mail-test endpoint.
- Attacker-controlled input reaches
From,Sender, or an equivalent envelope-sender value. - The PHP and operating-system environment permits the resulting command execution to have useful effect.
A system may contain old code yet avoid this path because it uses SMTP, keeps sender values fixed, or leaves the library unused. Conversely, a current CMS can still be exposed if a plugin, extension, vendor bundle, or manually copied library carries an old PHPMailer version.
Joomla, WordPress, and bundled copies
NVD lists PHPMailer through 5.2.17, Joomla 1.5.0 through 3.6.5, and WordPress through 4.7 in affected-configuration data. These ranges are not a verdict that every installation in them has the same remotely exploitable path. Bundled library versions, extensions, transport configuration, input validation, and endpoint reachability determine exposure. NVD affected configurations
Joomla specifically warns that extensions which bundle their own PHPMailer copy, or which bypass Joomla’s mail API, require independent checking. Updating the core application alone may not replace those copies. Joomla security advisory
Check the deployed dependency
Composer-managed installations
composer show phpmailer/phpmailer
composer why phpmailer/phpmailer
composer audit
Use the installed version, dependency path, and composer.lock as evidence. composer.json alone may describe a range rather than the package actually deployed. Audit output depends on the Composer version and configured package sources.
Manually bundled or CMS copies
find /var/www -iname '*phpmailer*' 2>/dev/null
grep -R "VERSION|VERSION_MAJOR|VERSION_MINOR" /var/www 2>/dev/null | grep -i phpmailer
Search vendor directories, extensions, plugins, uploads, and custom application trees. Multiple copies can coexist; determine which one the runtime autoloader selects.
PC Slower Than It Used to Be?
A free scan shows the junk files, broken settings and background clutter dragging Windows down - then fixes them in one click.Free scan · Windows 10 & 11Outdated Drivers Are Slowing You Down
One free scan finds every outdated or missing driver and matches the right update for your exact hardware.Free scan · exact hardware matchConfirm the transport and data flow
grep -RniE 'isMail|mailSend|Mailer[[:space:]]*=|PHPMailer|mail[[:space:]]*(' /var/www 2>/dev/null
Search results show possible reachability, not proof of exploitation. Confirm configuration and runtime behavior in a controlled staging environment. Look for native mail() selection, dynamic transport settings, and user values assigned to sender fields.
Remediation plan
- Inventory every copy. Include Composer packages, CMS extensions, vendor directories, and custom bundles.
- Update the parent application or extension. Use its official update mechanism where it manages dependencies.
- Move to a supported PHPMailer branch. Respect the application’s PHP and framework constraints, then regenerate and deploy the lock file as appropriate.
- Remove duplicate or shadowed copies. Verify that the intended version is loaded at runtime.
- Test mail workflows. Exercise contact forms, password resets, queue workers, attachments, internationalized addresses, and delivery failures.
- Use SMTP only as a compensating control when necessary. Secure authentication, TLS certificate validation, outbound rules, rate limits, and sender semantics still require configuration.
Sending through SMTP can avoid the vulnerable native-mail() path; an advisory for CVE-2016-10045 lists SMTP to localhost as a workaround. It does not remove the need to patch PHPMailer or eliminate other mail-related risks. Related advisory
Do not blindly replace files in a CMS-managed installation. A later application update may overwrite the change or expect a vendor-specific patch.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Incident-response checks
If a vulnerable, reachable system existed, treat confirmed exploitation as possible host compromise rather than merely email abuse. Preserve evidence before logs rotate and review:
Best Value
- Web access logs for suspicious requests to contact, registration, password-reset, and mail-test endpoints.
- PHP and application error logs, including abnormal mail-command failures.
- Unexpected child processes launched by the web-server account.
- New or modified PHP files in web roots, upload, cache, and temporary directories.
- Cron jobs, systemd timers, SSH keys, shell history, and other persistence.
- Outbound network connections and unusual mail-delivery patterns.
- Credential use from the affected host after the suspected exploitation window.
Record file hashes and modification times. Rotate credentials from a trusted system when compromise is plausible, and rebuild from known-good images when integrity cannot be established. Public exploit material and a CISA KEV listing establish risk and exploitation relevance, not compromise of every installation.
Why a WAF is not the fix
WAF or IPS signatures can help block known requests, and Check Point documented IPS protection for this vulnerability, but network controls are defense in depth. They do not correct vulnerable code, protect internal endpoints, or remediate a host that was already compromised. Check Point advisory
Quick Recap
Final checklist
- Identify the actual PHPMailer version loaded in production.
- Find every bundled or extension-owned copy.
- Confirm whether
isMailis reachable and whether sender data is user-controlled. - Upgrade to a supported PHPMailer release; do not stop at 5.2.18.
- Test all mail workflows and verify the runtime dependency after deployment.
- Use secured SMTP only as a temporary compensating measure when appropriate.
- Review logs, files, processes, outbound traffic, and credentials if exposure was possible.
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.




