Impact
AcyMailing SMTP Newsletter plugin for WordPress contains a stored cross‑site scripting vulnerability that allows an attacker to inject malicious JavaScript payloads into the database. When an affected newsletter page is rendered, the stored script executes in the victim’s browser, potentially exposing session data, defacing the site, or facilitating further attacks. The weakness corresponding to CWE‑79 and impacts the confidentiality, integrity, and availability of user interactions with the newsletter feature.
Affected Systems
The flaw is present in AcyMailing SMTP Newsletter version 10.11.0 and). The product is produced by AcyMailing Newsletter Team and is installed as a WordPress plugin.
Risk and Exploitability
The CVSS score of 7.1 indicates a high severity. The EPSS score of less than 1% reflects a very low probability of exploitation at the time of this analysis, and the vulnerability is not listed in the CISA KEV catalog. The likely attack vector is through the newsletter creation interface or other administrative area where user‑supplied content is stored; any authenticated or unauthenticated user who views the compromised page will be affected.
OpenCVE Enrichment