PatchSiren cyber security CVE debrief
CVE-2026-16636 wpmanageninja CVE debrief
The FluentSMTP – WP SMTP Plugin with Amazon SES, SendGrid, MailGun, Postmark, Google and Any SMTP Provider plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Recipient Display Name (to.name) in Email Logs in all versions up to, and including, 2.2.95. This vulnerability allows unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. The payload is delivered via an attacker-controlled recipient display name (to.name) in a wp_mail() call and does not fire in the log list view — only in the detail view when an administrator uses the Prev/Next navigation controls. To address this vulnerability, administrators and users of the plugin should prioritize updating to a patched version to prevent potential XSS attacks. Additionally, reviewing email logs for potential injected scripts and monitoring for unusual administrator activity, especially when using the Prev/Next navigation controls in the log detail view, is recommended.
- Vendor
- wpmanageninja
- Product
- FluentSMTP – WP SMTP Plugin with Amazon SES, SendGrid, Mailgun, Postmark, Cloudflare, toSend, Gmail and Any SMTP
- CVSS
- HIGH 7.2
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-08-06
- Original CVE updated
- 2026-08-06
- Advisory published
- 2026-08-06
- Advisory updated
- 2026-08-06
Who should care
Administrators and users of the FluentSMTP – WP SMTP Plugin with Amazon SES, SendGrid, MailGun, Postmark, Google and Any SMTP Provider plugin for WordPress, especially those using version 2.2.95 or earlier.
Technical summary
The FluentSMTP – WP SMTP Plugin with Amazon SES, SendGrid, MailGun, Postmark, Google and Any SMTP Provider plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Recipient Display Name (to.name) in Email Logs in all versions up to, and including, 2.2.95. The payload is delivered via an attacker-controlled recipient display name (to.name) in a wp_mail() call and does not fire in the log list view — only in the detail view when an administrator uses the Prev/Next navigation controls.
Defensive priority
Administrators and users of the FluentSMTP – WP SMTP Plugin with Amazon SES, SendGrid, MailGun, Postmark, Google and Any SMTP Provider plugin for WordPress should prioritize updating to a patched version to prevent potential XSS attacks.
Recommended defensive actions
- Update the FluentSMTP – WP SMTP Plugin with Amazon SES, SendGrid, MailGun, Postmark, Google and Any SMTP Provider plugin to a version beyond 2.2.95.
- Review email logs for potential injected scripts.
- Monitor for unusual administrator activity, especially when using the Prev/Next navigation controls in the log detail view.
- Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up.
- Review the supplied official advisory or CVE record to validate affected scope, severity, and vendor guidance.
- Plan vendor-supported updates or mitigations through normal change control where exposure is confirmed.
- Check relevant monitoring, detection, and logs for exposed assets that need extra review.
Evidence notes
The FluentSMTP – WP SMTP Plugin with Amazon SES, SendGrid, MailGun, Postmark, Google and Any SMTP Provider plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Recipient Display Name (to.name) in Email Logs in all versions up to, and including, 2.2.95 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-16636 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-16636
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-16636 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-16636
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source reference
Unverified legacy reference
URL: https://plugins.trac.wordpress.org/browser/fluent-smtp/tags/2.2.95/app/Models/Logger.php
-
Source reference
Unverified legacy reference
URL: https://plugins.trac.wordpress.org/browser/fluent-smtp/tags/2.2.95/app/Models/Logger.php
-
Source reference
Unverified legacy reference
URL: https://plugins.trac.wordpress.org/browser/fluent-smtp/tags/2.2.95/app/Services/Mailer/BaseHandler.php
-
Source reference
Unverified legacy reference
URL: https://plugins.trac.wordpress.org/browser/fluent-smtp/tags/2.2.95/app/Services/Mailer/BaseHandler.php
-
Source reference
Unverified legacy reference
URL: https://plugins.trac.wordpress.org/browser/fluent-smtp/tags/2.2.95/assets/admin/js/fluent-mail-admin-app.js
-
Source reference
Unverified legacy reference
URL: https://plugins.trac.wordpress.org/changeset/3635135/fluent-smtp/trunk/assets/admin/js/fluent-mail-admin-app.js
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.