CVE-2026-81764
—Unauthenticated XSS in WordPress Email Essentials Plugin
CVE-2026-81764 is an unauthenticated Cross-Site Scripting (XSS) flaw (CWE-79) in the Email Essentials WordPress plugin, affecting all versions up to and including 6.0.6. Because the issue requires no authentication, any attacker who can reach the affected site can craft a request or link that causes malicious JavaScript to execute in a visitor's or admin's browser when they interact with the attacker-supplied content. Successful exploitation could allow the attacker to run actions in the context of the victim's session, potentially hijack sessions, redirect users, or make limited changes or disclosures within the page (reflected in the CVSS low confidentiality/integrity/availability impacts and changed scope). Any WordPress site running Email Essentials 6.0.6 or earlier is affected. There are currently no known public proofs of concept, no CISA KEV listing, and no confirmed exploitation in the wild; EPSS estimates only a 0.2% probability of exploitation in the next 30 days.
What to do: Update the Email Essentials plugin to the latest available release (any version later than 6.0.6) as soon as a patched version is published. Until then, review the site's access logs for suspicious unauthenticated requests involving the plugin, and check recently created or modified content for unexpected scripts or links. As a general mitigation for unauthenticated XSS, keep user-facing inputs sanitized and consider temporarily deactivating the plugin if it is not essential.
| Email Essentials | <= 6.0.6 |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Unauthenticated Cross Site Scripting (XSS) in Email Essentials <= 6.0.6 versions.
- Ecosystems
- WordPress
- Weakness
- CWE-79
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L
In the news0 stories
No ingested article mentions this CVE yet.