Unauthenticated Cross Site Scripting Vulnerability in weMail Plugin by WordPress
CVE-2026-57322
7.1HIGH
What is CVE-2026-57322?
An unauthenticated Cross Site Scripting (XSS) vulnerability exists in the weMail plugin for WordPress, affecting versions up to 2.1.2. This vulnerability allows attackers to inject malicious scripts into web pages, which can execute in the browsers of users who visit the affected site. If successfully exploited, this can lead to unauthorized data access and potentially compromise user accounts.
Affected Version(s)
weMail <= 2.1.2