ZeroHour

CVE-2026-81764

Unauthenticated XSS in WordPress Email Essentials Plugin

CVSS 3.1
7.1 high
EPSS
<1%p8
Published
()
Modified
AI analysis

CVE-2026-81764 is an unauthenticated Cross-Site Scripting (XSS) flaw (CWE-79) in the Email Essentials WordPress plugin, affecting all versions up to and including 6.0.6. Because the issue requires no authentication, any attacker who can reach the affected site can craft a request or link that causes malicious JavaScript to execute in a visitor's or admin's browser when they interact with the attacker-supplied content. Successful exploitation could allow the attacker to run actions in the context of the victim's session, potentially hijack sessions, redirect users, or make limited changes or disclosures within the page (reflected in the CVSS low confidentiality/integrity/availability impacts and changed scope). Any WordPress site running Email Essentials 6.0.6 or earlier is affected. There are currently no known public proofs of concept, no CISA KEV listing, and no confirmed exploitation in the wild; EPSS estimates only a 0.2% probability of exploitation in the next 30 days.

What to do: Update the Email Essentials plugin to the latest available release (any version later than 6.0.6) as soon as a patched version is published. Until then, review the site's access logs for suspicious unauthenticated requests involving the plugin, and check recently created or modified content for unexpected scripts or links. As a general mitigation for unauthenticated XSS, keep user-facing inputs sanitized and consider temporarily deactivating the plugin if it is not essential.

Affected
Email Essentials<= 6.0.6
Estimated exposure
No basis for an estimate.

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Unauthenticated Cross Site Scripting (XSS) in Email Essentials <= 6.0.6 versions.

Ecosystems
WordPress
Weakness
CWE-79
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L

In the news

No ingested article mentions this CVE yet.