{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","feed_url":"https://feed.craftedsignal.io/products/fluentsmtp--wp-smtp-plugin-with-amazon-ses-sendgrid-mailgun-postmark-google-and-any-smtp-provider--2.2.95/feed.json","home_page_url":"https://feed.craftedsignal.io/","items":[{"_cs_actors":[],"_cs_cpes":[],"_cs_cves":[{"cvss":7.2,"id":"CVE-2026-16636"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["FluentSMTP – WP SMTP Plugin with Amazon SES, SendGrid, MailGun, Postmark, Google and Any SMTP Provider (\u003c= 2.2.95)"],"_cs_severities":["high"],"_cs_tags":["xss","web-vulnerability","wordpress"],"_cs_type":"advisory","_cs_vendors":["FluentSMTP"],"content_html":"\u003cp\u003eThe FluentSMTP plugin for WordPress, specifically versions up to and including 2.2.95, contains a stored cross-site scripting (XSS) vulnerability. The issue stems from insufficient input sanitization and output escaping of the 'to.name' parameter when processing email logs through wp_mail() calls. Unauthenticated attackers can inject arbitrary web scripts into these logs, which are subsequently rendered in the WordPress administrative interface.\u003c/p\u003e\n\u003cp\u003eCrucially, while the primary list view of email logs utilizes an escapeHtml pipeline to prevent script execution, the detail view accessed via 'Prev' or 'Next' navigation controls fails to apply this security control. When an administrator navigates through email details, the injected payload triggers, allowing for arbitrary JavaScript execution in the context of the administrator's browser session. This vulnerability poses a significant risk to WordPress site integrity by enabling session hijacking or unauthorized administrative actions.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation allows unauthenticated attackers to execute arbitrary JavaScript within the administrative session of a WordPress site. This can lead to account takeover, the creation of rogue administrator accounts, or unauthorized modifications to site content or settings. Given the ubiquity of WordPress and the function of SMTP plugins, a large number of installations are potentially susceptible if they remain unpatched.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eUpdate the FluentSMTP plugin to the latest version available beyond 2.2.95 to remediate the sanitization flaw.\u003c/li\u003e\n\u003cli\u003eMonitor administrative access logs for unusual login patterns or the creation of new user accounts shortly after potential XSS trigger events.\u003c/li\u003e\n\u003cli\u003eAudit WordPress logs for suspicious input contained within the 'to.name' fields of email logging tables.\u003c/li\u003e\n\u003cli\u003eDeploy a Web Application Firewall (WAF) to detect and block common XSS payloads in request parameters.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-08-06T05:21:52Z","date_published":"2026-08-06T05:21:52Z","id":"https://feed.craftedsignal.io/briefs/2026-08-fluentsmtp-xss/","summary":"An unauthenticated stored cross-site scripting vulnerability in the FluentSMTP WordPress plugin allows attackers to inject malicious scripts into email logs that execute in an administrator session.","title":"Stored XSS in FluentSMTP WordPress Plugin via Email Logs","url":"https://feed.craftedsignal.io/briefs/2026-08-fluentsmtp-xss/"}],"language":"en","title":"CraftedSignal Threat Feed - FluentSMTP – WP SMTP Plugin With Amazon SES, SendGrid, MailGun, Postmark, Google and Any SMTP Provider (\u003c= 2.2.95)","version":"https://jsonfeed.org/version/1.1"}