CVE-2026-57741: WordPress AcyMailing SMTP Newsletter plugin <= 10.11.0 - Cross Site Scripting (XSS) vulnerability
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in AcyMailing Newsletter Team AcyMailing SMTP Newsletter acymailing allows Stored XSS.This issue affects AcyMailing SMTP Newsletter: from n/a through <= 10.11.0.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-57741?
CVE-2026-57741 has a severity rating of high, classified as a 7.1 based on its potential impact.
How do I fix CVE-2026-57741?
To fix CVE-2026-57741, upgrade the AcyMailing SMTP Newsletter plugin to version 10.11.1 or later.
What type of vulnerability is CVE-2026-57741?
CVE-2026-57741 is classified as a Cross Site Scripting (XSS) vulnerability.
Who is affected by CVE-2026-57741?
CVE-2026-57741 affects users of AcyMailing SMTP Newsletter plugin versions from n/a up to and including 10.11.0.
What can happen if CVE-2026-57741 is exploited?
Exploiting CVE-2026-57741 could allow attackers to execute arbitrary scripts in the context of the affected user’s session.