MEDIUM
retainful
CVE published 2026-10-10
CVE-2026-97396
The Email Marketing for WordPress and WooCommerce – Retainful plugin, up to and including version 1.0.10, is vulnerable to Stored Cross-Site Scripting via the 'data' parameter. This vulnerability allows authenticated attackers with subscriber-level access to inject arbitrary web scripts that execute when users access injected pages. Defenders should assess exposure and prioritize patching or mitigation to [truncated]