PatchSiren

retainful CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

MEDIUM retainful CVE published 2026-10-10

CVE-2026-97396

The Email Marketing for WordPress and WooCommerce – Retainful plugin, up to and including version 1.0.10, is vulnerable to Stored Cross-Site Scripting via the 'data' parameter. This vulnerability allows authenticated attackers with subscriber-level access to inject arbitrary web scripts that execute when users access injected pages. Defenders should assess exposure and prioritize patching or mitigation to [truncated]