Junglewise Threat Intelligence

CVE-2026-8089: weMail WordPress plugin Reflected XSS in wemail_preview AJAX action

CVE-2026-8089 · Severity: high · CVSS 7.1 · Published 2026-06-17

Executive brief

A security vulnerability in the weMail WordPress plugin, used for email marketing and newsletters, could allow an attacker to take over a website. By tricking an administrator into clicking a malicious link, an attacker can execute hidden commands in the administrator's browser. This can be used to create new unauthorized administrator accounts or steal sensitive site data.

Technical details

A Reflected Cross-Site Scripting (XSS) vulnerability exists in the weMail plugin for WordPress due to insufficient sanitization of the 'form_id' parameter in the 'wemail_preview' AJAX action. While the plugin uses sanitize_text_field(), this function does not encode double quotes, allowing an attacker to break out of HTML attributes in the response. Because the AJAX response is not protected by a nonce and includes a valid 'wp_rest' nonce in the payload, an unauthenticated attacker can craft a URL that, when visited by an authenticated administrator, executes arbitrary JavaScript. This can be leveraged to perform a one-shot account takeover by using the reflected REST API nonce to create a new administrator user.

Affected products

  • weMail weMail: Email Marketing, Email Automation, Newsletters, Subscribers & Email Optins for WooCommerce < 2.1.3

Timeline

  • 2026-03-10: other: Initial discovery or related activity mentioned in references
  • 2026-05-27: disclosed: Vulnerability details made public by WPScan
  • 2026-06-17: advisory: CVE published to NVD

References