CVE-2026-105061: WordPress WP Mailster plugin <= 1.9.0.0 - Cross Site Scripting (XSS) vulnerability
Published Oct 6, 2026
·Updated
Unauthenticated Cross Site Scripting (XSS) in WP Mailster <= 1.9.0.0 versions.
Affected Software
1 affected component
WordPress WP Mailster<=1.9.0.0
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
WordPress WP Mailster pluginto a version that resolves this vulnerability.Fixed in 1.9.1.0
Event History
Oct 6, 2026
CVE Published
via MITRE·08:35 AM
Data Sourced
via MITRE·08:35 AM
RemedyDescriptionSeverityWeakness
Data Sourced
via NVD·09:17 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
Can an attacker exploit this without a WordPress account?
Yes. The vulnerability is identified as unauthenticated, and the vector specifies that no privileges are required.
2
Does exploitation require interaction from another user?
Yes. The CVSS vector lists user interaction as required.
3
Which deployments should be treated as affected?
WordPress sites using WP Mailster version 1.9.0.0 or earlier should be treated as affected based on the available information.
4
What is the stated impact if exploitation succeeds?
The CVSS vector indicates low impacts to confidentiality, integrity, and availability, with scope changed.