Stored Cross-Site Scripting in MailerPress Plugin for WordPress
CVE-2026-8599
6.4MEDIUM
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 9 June 2026
What is CVE-2026-8599?
The MailerPress plugin for WordPress has a vulnerability that allows authenticated users with author-level access to inject arbitrary web scripts via the Campaign HTML Content Field. This occurs due to inadequate input sanitization and output escaping. The vulnerability affects the admin dashboard preview, permitting potentially harmful scripts to execute when an administrator views an injected campaign. It's important to note that the campaign preview endpoint is protected by a Content-Security-Policy header, which blocks all inline scripts from executing in public-facing views.
Affected Version(s)
MailerPress β Email Marketing, Newsletter, Email Automation & WooCommerce Emails 0 <= 2.0.4