Description
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in SiteGround SiteGround Email Marketing siteground-email-marketing allows Stored XSS.This issue affects SiteGround Email Marketing: from n/a through <= 1.7.5.
Published: 2026-07-13
Score: 7.1 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The SiteGround Email Marketing plugin for WordPress contains a stored cross‑site scripting flaw that allows malicious JavaScript into data stored by the plugin. When other users view the affected pages, the stored scripts execute in their browsers, potentially exposing session information or enabling further attacks. This weakness falls under CWE‑79, signifying improper input neutralization during web page generation.

Affected Systems

SiteGround site owners who have installed the SiteGround Email Marketing plugin on their WordPress installations and are using version 1.7.5 or earlier are affected. No other WordPress plugins or site components are listed as vulnerable, and the issue is confined to the plugin itself.

Risk and Exploitability

The CVSS base score of 7.1 indicates a high‑severity vulnerability, while the EPSS score of less than 1 % signals a low current exploitation probability. The vulnerability is not recorded in the CISA KEV catalog. The detail the exact attack vector or required privileges, but it is inferred to the plugin’s web interface could leverage the flaw. Likely, the attacker would need authenticated access to the backend where the input is processed.

Generated by OpenCVE AI on July 31, 2026 at 11:52 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade the SiteGround Email Marketing plugin to a version newer than 1.7.5.
  • Restrict access to the plugin’s administrative interface to trusted users only and enforce strong authentication.
  • Implement input validation and sanitization for any data stored by the plugin, or apply a content security policy that blocks the execution of untrusted scripts.

Generated by OpenCVE AI on July 31, 2026 at 11:52 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 13 Jul 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 13 Jul 2026 13:30:00 +0000

Type Values Removed Values Added
First Time appeared Siteground
Siteground email-marketing
Wordpress
Wordpress wordpress
Vendors & Products Siteground
Siteground email-marketing
Wordpress
Wordpress wordpress

Mon, 13 Jul 2026 10:00:00 +0000

Type Values Removed Values Added
Description Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in SiteGround SiteGround Email Marketing siteground-email-marketing allows Stored XSS.This issue affects SiteGround Email Marketing: from n/a through <= 1.7.5.
Title WordPress SiteGround Email Marketing plugin <= 1.7.5 - Cross Site Scripting (XSS) vulnerability
Weaknesses CWE-79
References
Metrics cvssV3_1

{'score': 7.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L'}


Subscriptions

Siteground Email-marketing
Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-07-13T13:43:57.427Z

Reserved: 2026-06-24T12:46:38.624Z

Link: CVE-2026-57416

cve-icon Vulnrichment

Updated: 2026-07-13T13:43:51.581Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-31T12:00:05Z

Weaknesses
  • CWE-79

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')