Cross Site Scripting Vulnerability in AcyMailing SMTP Newsletter Plugin
CVE-2026-28182

6.5MEDIUM

Key Information:

Vendor

WordPress

Vendor
CVE Published:
13 August 2026

What is CVE-2026-28182?

The AcyMailing SMTP Newsletter plugin versions prior to 10.11.1 are susceptible to a Cross Site Scripting (XSS) vulnerability. This issue allows attackers to inject malicious scripts into the newsletter content, which can then be executed in the context of authenticated users or administrators. Proper sanitization and validation measures are essential to mitigate this risk and ensure secure operations for WordPress installations utilizing this plugin.

Affected Version(s)

AcyMailing SMTP Newsletter <= 10.11.1

References

CVSS V3.1

Score:
6.5
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Asim Alshaya | Patchstack Bug Bounty Program
.