Executive brief
The SendPulse Email Marketing Newsletter plugin for WordPress, which helps businesses manage email campaigns and subscription forms, contains a security flaw. This vulnerability allows users with low-level access (such as contributors) to inject malicious scripts into the website's pages. If exploited, these scripts could run in the browsers of other visitors, including site administrators, potentially leading to unauthorized actions or data theft.
Technical details
The SendPulse Email Marketing Newsletter plugin for WordPress is vulnerable to Stored Cross-Site Scripting (XSS) via the '_sp_form_code' Post Meta field. The vulnerability exists in all versions up to and including 2.2.5 due to insufficient input sanitization and output escaping of form code. Authenticated attackers with contributor-level permissions or higher can exploit this by creating a 'sendpulse_form' post that includes a legitimate SendPulse loader script tag paired with malicious HTML (such as an 'img' tag with an 'onerror' attribute). This combination bypasses the plugin's allow-list check, allowing the script to execute in the context of any user, including administrators, who views or previews a page containing the [sendpulse-form] shortcode. As of the advisory date, users should ensure they are running a version higher than 2.2.5 if available.
Affected products
- SendPulse SendPulse Email Marketing Newsletter up to, and including, 2.2.5
Timeline
- 2026-08-01: disclosed: NVD publication date
References
- https://plugins.trac.wordpress.org/browser/sendpulse-email-marketing-newsletter/tags/2.2.5/inc/class-senpulse-newsletter-forms.php
- https://plugins.trac.wordpress.org/browser/sendpulse-email-marketing-newsletter/tags/2.2.5/inc/class-senpulse-newsletter-shortcodes.php
- https://www.wordfence.com/threat-intel/vulnerabilities/id/4bae687b-5b54-4151-871e-7a9b6e56986e?source=cve