CVE-2026-57416: WordPress SiteGround Email Marketing plugin <= 1.7.5 - Cross Site Scripting (XSS) vulnerability
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in SiteGround SiteGround Email Marketing siteground-email-marketing allows Stored XSS.This issue affects SiteGround Email Marketing: from n/a through <= 1.7.5.
Affected Software
Event History
Frequently Asked Questions
Which versions are known to be affected?
The affected range includes SiteGround Email Marketing versions through 1.7.5; no unaffected fixed version is provided in the available data.
What does an attacker need to exploit this issue?
The CVSS vector indicates network-reachable exploitation with low attack complexity, no privileges required, and user interaction required. The available data does not identify the specific input field, workflow, or user action involved.
What is the likely impact if exploitation succeeds?
This is a stored XSS issue, meaning injected script may be retained and later executed when a user views the affected generated web content. The impact rating indicates potential low confidentiality, integrity, and availability impact, with scope changed.