Impact
The affected MailerPress plugin is vulnerable to stored cross‑site scripting through the Campaign HTML Content field. Insufficient input sanitization and output escaping allow an authenticated attacker with author‑level access or higher to inject arbitrary JavaScript that executes when an admin previews a campaign. The stored payload remains in the database and will run for any user who visits the preview page, potentially enabling script execution, session hijacking, or defacement within the WordPress admin environment.
Affected Systems
The MailerPress – Email Marketing, Newsletter, Email Automation & WooCommerce Emails plugin for WordPress is affected in all releases up to and including version 2.0.4. Users running these versions on any WordPress installation are susceptible if they possess author or higher permissions.
Risk and Exploitability
The vulnerability carries a CVSS score of 6.4, indicating moderate severity. No EPSS score is available, and the issue is not listed in the CISA KEV catalog. Exploitation requires authenticated access; an attacker must first create or edit a campaign, then an admin or user with preview privileges must view the affected campaign preview page. The limited attack surface and necessity of a privileged user typically reduce the overall exploitation risk, though the potential impact on the admin interface remains significant.
OpenCVE Enrichment