{
 "id": "WPSEC-2026-0500",
 "url": "https://wpsec.com/vuln/WPSEC-2026-0500/",
 "json_url": "https://wpsec.com/vuln/WPSEC-2026-0500/advisory.json",
 "markdown_url": "https://wpsec.com/vuln/WPSEC-2026-0500/index.md",
 "title": "MailPoet – Newsletters, Email Marketing, and Automation <= 5.40.0 - Authenticated (Editor+) Stored Cross-Site Scripting via Newsletter Style Settings",
 "description": "The MailPoet plugin for WordPress is vulnerable to Stored Cross-Site Scripting via newsletter global style settings in all versions up to, and including, 5.40.0. This is due to style property names, values and selectors from a newsletter's saved global styles being written into the rendered newsletter's <style> element without validation, allowing a value to close the style element. This makes it possible for authenticated attackers with access to manage MailPoet emails, which by default includes Editors, to inject arbitrary web scripts that execute when a user views the rendered newsletter, such as its view-in-browser page or preview. This only affects multi-site installations and installations where unfiltered_html has been disabled.",
 "plugin": {
  "slug": "mailpoet",
  "name": "MailPoet – Newsletters, Email Marketing, and Automation",
  "full_name": "MailPoet – Newsletters, Email Marketing, and Automation",
  "wordpress_org": "https://wordpress.org/plugins/mailpoet/",
  "advisories_url": "https://wpsec.com/vuln/plugin/mailpoet/",
  "attacksurface": "https://attacksurface.wpsec.com/plugin/mailpoet"
 },
 "type": "XSS",
 "cwe": [
  "CWE-79"
 ],
 "cve": [],
 "cvss": {
  "version": "3.1",
  "score": 4.4,
  "vector": "CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:C/C:L/I:L/A:N",
  "severity": "Medium"
 },
 "affected": {
  "ranges": [
   {
    "from": null,
    "from_inclusive": true,
    "to": "5.41.0",
    "to_inclusive": false
   }
  ],
  "text": [
   "all versions before 5.41.0"
  ]
 },
 "introduced_in": null,
 "fixed_in": "5.41.0",
 "remediation": "Update to 5.41.0 or later.",
 "fix_released": "2026-10-06T10:35:00+00:00",
 "published": "2026-10-07T10:52:45+00:00",
 "updated": "2026-10-06T14:18:49.760131+00:00",
 "also_published_as": null,
 "references": [
  "https://wpsec.com/vuln/WPSEC-2026-0500/",
  "https://plugins.svn.wordpress.org/mailpoet/tags/5.41.0/",
  "https://wordpress.org/plugins/mailpoet/"
 ],
 "attacksurface_url": "https://attacksurface.wpsec.com/plugin/mailpoet",
 "source": "WPSec",
 "license": {
  "name": "CC BY 4.0",
  "url": "https://creativecommons.org/licenses/by/4.0/"
 },
 "usage": {
  "plugin": "Medium",
  "affected_versions": "Medium",
  "as_of": "2026-10-07"
 }
}