Cross-site Scripting Vulnerability in AcyMailing SMTP Newsletter by Datasolution
CVE-2026-105318

7.1HIGH

Key Information:

Vendor

WordPress

Vendor
CVE Published:
9 October 2026

What is CVE-2026-105318?

The AcyMailing SMTP Newsletter plugin by Datasolution is susceptible to a Cross-site Scripting vulnerability, which allows attackers to inject malicious scripts into web pages generated by the plugin. This reflected XSS issue affects versions up to 11.1.0, potentially exposing users to unauthorized access to sensitive information when they interact with compromised content.

Affected Version(s)

AcyMailing SMTP Newsletter 0 <= 11.1.0

References

CVSS V3.1

Score:
7.1
Severity:
HIGH
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Peter Tang | Patchstack Bug Bounty Program
.