Stored Cross-Site Scripting in CM E-Mail Blacklist Plugin for WordPress
CVE-2026-0691
4.4MEDIUM
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 17 January 2026
What is CVE-2026-0691?
The CM E-Mail Blacklist plugin for WordPress is susceptible to Stored Cross-Site Scripting vulnerabilities via the 'black_email' parameter. This issue arises from inadequate input sanitization and output escaping, allowing authenticated attackers with administrator-level permissions to inject malicious web scripts into pages. Consequently, these scripts execute whenever a user accesses the compromised page. This vulnerability specifically affects installations with multi-site configurations and where the unfiltered_html feature has been disabled.
Affected Version(s)
CM E-Mail Blacklist β Simple email filtering for safer registration 0 <= 1.6.2