Junglewise Threat Intelligence

CVE-2026-66606: SmartSMTP unauthenticated cross-site scripting

CVE-2026-66606 · Severity: high · CVSS 7.1 · Published 2026-08-20

Vendors: ThemeGrill.

Executive brief

SmartSMTP is a WordPress plugin used for email functionality on websites. An unauthenticated attacker can inject malicious scripts into affected sites through cross-site scripting (XSS), allowing them to steal visitor data, hijack accounts, or compromise website visitors without requiring the attacker to have admin access.

Technical details

This is a stored or reflected cross-site scripting (XSS) vulnerability in the SmartSMTP WordPress plugin affecting versions 1.2.0 and earlier. The vulnerability requires an unauthenticated attacker to craft a malicious input, but successful exploitation requires user interaction (e.g., a privileged user clicking a malicious link or visiting a crafted page). The attacker can inject arbitrary JavaScript that executes in victims' browsers, enabling data theft or account hijacking. A patch is available in version 1.2.1 and later.

Affected products

  • ThemeGrill SmartSMTP <=1.2.0

Timeline

  • 2026-08-19: disclosed
  • 2026-08-19: patched: Version 1.2.1 or later available

References