Junglewise Threat Intelligence

CVE-2026-57416: SiteGround SiteGround Email Marketing stored XSS

CVE-2026-57416 · Severity: high · CVSS 7.1 · Published 2026-07-13

Executive brief

The SiteGround Email Marketing plugin for WordPress is vulnerable to a security flaw that allows attackers to inject malicious scripts into a website. This plugin is used by site owners to manage email campaigns and subscriber lists. If exploited, an attacker could redirect visitors to malicious websites, steal session information, or deface the site, potentially damaging the organization's reputation and compromising user data.

Technical details

A stored cross-site scripting (XSS) vulnerability exists in the SiteGround Email Marketing plugin for WordPress due to improper neutralization of input during web page generation. The flaw allows an unauthenticated remote attacker to inject malicious scripts (such as redirects or advertisements) into the website. Successful exploitation requires a privileged user to interact with the malicious content, such as visiting a specific page or clicking a link. Once executed, the script runs in the context of the victim's browser, potentially leading to session hijacking or unauthorized actions. The issue is fixed in version 1.7.6.

Affected products

  • SiteGround SiteGround Email Marketing through 1.7.5

Timeline

  • 2026-05-18: other: Vulnerability reported by researcher xwii
  • 2026-07-08: advisory: Patchstack advisory published
  • 2026-07-13: disclosed: CVE published to NVD dataset
  • 2026-07-13: patched: Patch confirmed available in version 1.7.6

References