Impact
The SiteGround Email Marketing plugin for WordPress contains a stored cross‑site scripting flaw that allows malicious JavaScript into data stored by the plugin. When other users view the affected pages, the stored scripts execute in their browsers, potentially exposing session information or enabling further attacks. This weakness falls under CWE‑79, signifying improper input neutralization during web page generation.
Affected Systems
SiteGround site owners who have installed the SiteGround Email Marketing plugin on their WordPress installations and are using version 1.7.5 or earlier are affected. No other WordPress plugins or site components are listed as vulnerable, and the issue is confined to the plugin itself.
Risk and Exploitability
The CVSS base score of 7.1 indicates a high‑severity vulnerability, while the EPSS score of less than 1 % signals a low current exploitation probability. The vulnerability is not recorded in the CISA KEV catalog. The detail the exact attack vector or required privileges, but it is inferred to the plugin’s web interface could leverage the flaw. Likely, the attacker would need authenticated access to the backend where the input is processed.
OpenCVE Enrichment