Stored Cross-Site Scripting in MailerPress Plugin for WordPress
CVE-2026-8599

6.4MEDIUM

What is CVE-2026-8599?

The MailerPress plugin for WordPress has a vulnerability that allows authenticated users with author-level access to inject arbitrary web scripts via the Campaign HTML Content Field. This occurs due to inadequate input sanitization and output escaping. The vulnerability affects the admin dashboard preview, permitting potentially harmful scripts to execute when an administrator views an injected campaign. It's important to note that the campaign preview endpoint is protected by a Content-Security-Policy header, which blocks all inline scripts from executing in public-facing views.

Affected Version(s)

MailerPress – Email Marketing, Newsletter, Email Automation & WooCommerce Emails 0 <= 2.0.4

References

CVSS V3.1

Score:
6.4
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Faizan Shaik
.