CVE-2026-8089: weMail < 2.1.3 - Reflected Cross-Site Scripting
The weMail: Email Marketing, Email Automation, Newsletters, Subscribers & Email Optins for WooCommerce WordPress plugin before 2.1.3 does not properly escape a user-supplied parameter before reflecting it into an HTML attribute on a non-nonce-protected AJAX response, allowing unauthenticated attackers to deliver Reflected Cross-Site Scripting against any authenticated user (including administrators) via a crafted URL.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
weMail: Email Marketing, Email Automation, Newsletters, Subscribers & Email Optins for WooCommerce (WordPress plugin)to a version that resolves this vulnerability.Fixed in 2.1.3
Event History
Frequently Asked Questions
What is the severity of CVE-2026-8089?
CVE-2026-8089 has a severity rating of high with a CVSS score of 7.1.
How do I fix CVE-2026-8089?
To mitigate CVE-2026-8089, update the weMail plugin to version 2.1.3 or later.
What type of vulnerability is CVE-2026-8089?
CVE-2026-8089 is classified as a Reflected Cross-Site Scripting (XSS) vulnerability.
What impact does CVE-2026-8089 have?
CVE-2026-8089 allows unauthenticated attackers to execute scripts in the context of user sessions due to improper input handling.
Which software is affected by CVE-2026-8089?
CVE-2026-8089 affects the weMail plugin for WooCommerce WordPress prior to version 2.1.3.