Junglewise Threat Intelligence

CVE-2026-57741: AcyMailing SMTP Newsletter Stored XSS

CVE-2026-57741 · Severity: high · CVSS 7.1 · Published 2026-07-13

Technologies: AcyMailing Newsletter Team AcyMailing SMTP Newsletter. Vendors: AcyMailing Newsletter Team.

Executive brief

AcyMailing SMTP Newsletter, a popular WordPress plugin used for managing email marketing and newsletters, contains a security flaw that allows for stored cross-site scripting (XSS). An attacker could use this vulnerability to inject malicious scripts into the website, which would then execute in the browsers of other users or administrators. This could lead to unauthorized actions, theft of session cookies, or the defacement of the site.

Technical details

A Stored Cross-Site Scripting (XSS) vulnerability exists in the AcyMailing SMTP Newsletter plugin for WordPress (versions up to and including 10.11.0). The flaw stems from improper neutralization of user-supplied input during web page generation, allowing an attacker to inject persistent malicious scripts. The attack vector is network-based and requires a user to interact with the affected page (UI:R). Successful exploitation allows the attacker to execute arbitrary JavaScript in the context of the victim's browser, potentially leading to session hijacking or administrative account takeover. The issue is addressed in version 10.11.1.

Affected products

  • AcyMailing Newsletter Team AcyMailing SMTP Newsletter through 10.11.0

Timeline

  • 2026-07-13: disclosed
  • 2026-07-13: advisory

References