MEDIUM
sendpulse
CVE published 2026-08-01
CVE-2026-13362
AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-01T03:16:25.307Z and has not been modified since then. The SendPulse Email Marketing Newsletter plugin for WordPress is vulnerable to Stored Cross-Site Scripting via _sp_form_code Post Meta in all versions up to, and including, 2.2.5 due to insufficient input sanitization and output escaping. This m [truncated]