Description
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in AcyMailing Newsletter Team AcyMailing SMTP Newsletter acymailing allows Stored XSS.This issue affects AcyMailing SMTP Newsletter: from n/a through <= 10.11.0.
Published: 2026-07-13
Score: 7.1 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

AcyMailing SMTP Newsletter plugin for WordPress contains a stored cross‑site scripting vulnerability that allows an attacker to inject malicious JavaScript payloads into the database. When an affected newsletter page is rendered, the stored script executes in the victim’s browser, potentially exposing session data, defacing the site, or facilitating further attacks. The weakness corresponding to CWE‑79 and impacts the confidentiality, integrity, and availability of user interactions with the newsletter feature.

Affected Systems

The flaw is present in AcyMailing SMTP Newsletter version 10.11.0 and). The product is produced by AcyMailing Newsletter Team and is installed as a WordPress plugin.

Risk and Exploitability

The CVSS score of 7.1 indicates a high severity. The EPSS score of less than 1% reflects a very low probability of exploitation at the time of this analysis, and the vulnerability is not listed in the CISA KEV catalog. The likely attack vector is through the newsletter creation interface or other administrative area where user‑supplied content is stored; any authenticated or unauthenticated user who views the compromised page will be affected.

Generated by OpenCVE AI on August 1, 2026 at 10:34 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade the AcyMailing SMTP Newsletter plugin to a version newer than 10.11.0 as soon as the patch is available.
  • If an immediate update is not possible, disable the newsletter functionality or the plugin entirely to prevent execution of stored scripts until patching.
  • Review all user‑supplied fields in the plugin for proper input validation or sanitization, and ensure the WordPress core and other plugins are kept up to date to reduce overall risk.

Generated by OpenCVE AI on August 1, 2026 at 10:34 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 13 Jul 2026 15:00:00 +0000

Type Values Removed Values Added
First Time appeared Acymailing Newsletter Team
Acymailing Newsletter Team acymailing Smtp Newsletter
Wordpress
Wordpress wordpress
Vendors & Products Acymailing Newsletter Team
Acymailing Newsletter Team acymailing Smtp Newsletter
Wordpress
Wordpress wordpress

Mon, 13 Jul 2026 14:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 13 Jul 2026 10:00:00 +0000

Type Values Removed Values Added
Description Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in AcyMailing Newsletter Team AcyMailing SMTP Newsletter acymailing allows Stored XSS.This issue affects AcyMailing SMTP Newsletter: from n/a through <= 10.11.0.
Title WordPress AcyMailing SMTP Newsletter plugin <= 10.11.0 - Cross Site Scripting (XSS) vulnerability
Weaknesses CWE-79
References
Metrics cvssV3_1

{'score': 7.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L'}


Subscriptions

Acymailing Newsletter Team Acymailing Smtp Newsletter
Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-07-13T13:37:41.971Z

Reserved: 2026-06-25T08:04:29.578Z

Link: CVE-2026-57741

cve-icon Vulnrichment

Updated: 2026-07-13T13:37:36.991Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-01T10:45:03Z

Weaknesses
  • CWE-79

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')