Junglewise Threat Intelligence

CVE-2026-57322: weDevs weMail unauthenticated XSS

CVE-2026-57322 · Severity: high · CVSS 7.1 · Published 2026-06-26

Vendors: weDevs.

Executive brief

weMail is a WordPress plugin used for email marketing and newsletter management. A security vulnerability in versions 2.1.2 and earlier allows unauthenticated attackers to inject malicious scripts into the website. If a site administrator or visitor clicks a specially crafted link, the attacker could steal session information, redirect users to malicious sites, or perform unauthorized actions on the website.

Technical details

A reflected Cross-Site Scripting (XSS) vulnerability exists in the weDevs weMail plugin for WordPress (versions <= 2.1.2) due to improper neutralization of user-supplied input during web page generation (CWE-79). An unauthenticated remote attacker can exploit this by tricking a user into clicking a malicious link or visiting a crafted page. Successful exploitation allows the execution of arbitrary JavaScript in the context of the victim's browser session, potentially leading to session hijacking or unauthorized administrative actions. The issue is resolved in version 2.1.3.

Affected products

  • weDevs weMail <= 2.1.2

Timeline

  • 2026-01-20: other: Reported by Nguyen Ba Khanh
  • 2026-06-26: disclosed: Vulnerability published by Patchstack
  • 2026-06-26: patched: Patch released in version 2.1.3

References