cleantalk
Vulnerabilities and Security Researches

Vulnerabilities and security researches formailjet-for-wordpress mailjet-for-wordpress

Direction: descending
Oct 08, 2026

Mailjet Email Marketing # CVE-2026-39791

CVE, Research URL

CVE-2026-39791

Date
Oct 06, 2026
Research Description
Unauthenticated Sensitive Data Exposure in Mailjet Email Marketing <= 6.2.3 versions.
Affected versions
max 6.2.3.
Status
vulnerable
Jun 07, 2024

Mailjet Email Marketing # fd135b6d9545f4f161ad80ad33bc776604759116

Date
Jan 03, 2023
Research Description
Mailjet Email Marketing [mailjet-for-wordpress] < 5.3.1 Mailjet Email Marketing <= 5.3 - Authenticated (Admin+) Cross-Site Scripting The Mailjet Email Marketing plugin for WordPress is vulnerable to authenticated stored cross-site scripting in versions up to, and including, 5.3 via the 'mailjet_from_name' parameter. This allows authenticated attackers with administrator-level capabilities to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. 
Affected versions
max 5.3.1.
Status
vulnerable