CVE-2026-66606: WordPress SmartSMTP plugin <= 1.2.0 - Cross Site Scripting (XSS) vulnerability
Unauthenticated Cross Site Scripting (XSS) in SmartSMTP <= 1.2.0 versions.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
WordPress SmartSMTP pluginto a version that resolves this vulnerability.Fixed in 1.2.1
Event History
Frequently Asked Questions
What does an attacker need to exploit this issue?
The issue is described as unauthenticated, so no WordPress account or prior authentication is required. Exploitation does require user interaction, as reflected by the UI:R vector.
What is the potential impact if exploitation succeeds?
The CVSS vector indicates low-impact compromise of confidentiality, integrity, and availability, with scope changed. This means successful XSS could affect another security authority or context beyond the vulnerable component.
Which SmartSMTP versions are known to be affected?
SmartSMTP versions up to and including 1.2.0 are identified as affected. The provided data does not identify a fixed version.