PatchSiren cyber security CVE debrief
CVE-2026-13362 sendpulse CVE debrief
AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-01T03:16:25.307Z and has not been modified since then. The SendPulse Email Marketing Newsletter plugin for WordPress is vulnerable to Stored Cross-Site Scripting via _sp_form_code Post Meta in all versions up to, and including, 2.2.5 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. The vulnerability affects a wide range of users, including administrators, security teams, and operators, who should all take necessary precautions to prevent exploitation.
- Vendor
- sendpulse
- Product
- SendPulse Email Marketing Newsletter
- CVSS
- MEDIUM 6.4
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-08-01
- Original CVE updated
- 2026-08-01
- Advisory published
- 2026-08-01
- Advisory updated
- 2026-08-01
Who should care
WordPress administrators and users with contributor-level access who use the SendPulse Email Marketing Newsletter plugin, as well as security teams monitoring for potential exploitation attempts, should be aware of this vulnerability and take necessary precautions to prevent exploitation. This includes restricting contributor-level access, monitoring for suspicious activity, and regularly updating and patching the plugin. Additionally, security teams should review the plugin's configuration and ensure that it is properly secured. The vulnerability's impact on operators and platforms requires attention from security teams to prevent potential attacks. Vulnerability management and security teams should prioritize patching and monitoring to mitigate the risk of exploitation. Affected operators should also consider implementing compensating controls, such as Web Application Firewalls (WAFs), to detect and prevent XSS attacks. The vulnerability's technical details and potential impact on security teams necessitate a thorough review of the plugin's security configuration and the implementation of necessary security measures. Security teams should also track exceptions, retest remediated assets, and close the item only after evidence is documented. This vulnerability affects a wide range of users, including administrators, security teams, and operators, who should all take necessary precautions to prevent exploitation. The vulnerability's impact on security teams and operators requires a coordinated effort to prevent potential attacks and mitigate the risk of exploitation. Security teams should also consider the potential impact on their organization's overall security posture and take necessary measures to prevent exploitation. The SendPulse Email Marketing Newsletter plugin's vulnerability requires attention from a wide range of stakeholders, including administrators, security teams, and operators, to prevent potential attacks and mitigate the risk of exploitation. The vulnerability's technical details and potential impact on security teams necessitate a thorough review of the plugin's security configuration and the implementation of necessary security measures. The
Technical summary
The SendPulse Email Marketing Newsletter plugin for WordPress is vulnerable to Stored Cross-Site Scripting via _sp_form_code Post Meta in all versions up to, and including, 2.2.5. This allows authenticated attackers with contributor-level access to inject arbitrary web scripts, which execute when a user accesses an injected page. The vulnerability's technical details necessitate a thorough review of the plugin's security configuration and the implementation of necessary security measures. Security teams should prioritize patching and monitoring to mitigate the risk of exploitation.
Defensive priority
Authenticated attackers with contributor-level access could inject web scripts via the SendPulse Email Marketing Newsletter plugin, requiring user interaction to execute.
Recommended defensive actions
- Inventory and verify installed plugin versions.
- Restrict contributor-level access and monitor for suspicious post creations.
- Implement a Web Application Firewall (WAF) to detect and prevent XSS attacks.
- Regularly update and patch the SendPulse Email Marketing Newsletter plugin.
- Monitor for and respond to potential exploitation attempts.
Evidence notes
The SendPulse Email Marketing Newsletter plugin for WordPress has a stored XSS vulnerability due to insufficient input sanitization and output escaping. Authenticated attackers with contributor-level access can inject arbitrary web scripts, which execute when a user accesses an injected page. The vulnerability affects all versions up to, and including, 2.2.5. To verify, defenders should review the plugin version, check for suspicious post creations, and monitor for potential exploitation attempts.
Official resources
AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-01T03:16:25.307Z and has not been modified since then.