← WordPress Vulnerabilities
WordPress security by component

Email Essentials

Email Essentials (email-essentials) is a WordPress plugin with 1 published CVE record in this archive. The latest tracked vulnerability was published Aug 31, 2026; the highest published CVSS base score is 7.1.

Plugin slug: email-essentials

CVE-2026-81764: Email Essentials permits unauthenticated XSS

Email Essentials through 6.0.6 allows an unauthenticated attacker to inject script into affected output. The script executes when a victim interacts with that output and can act within the victim's browser session.

PublishedAug 31, 2026
Known safe version6.0.7
Published vulnerabilities for email-essentials
Safe version
Aug 31, 2026 CVE-2026-81764
Email Essentials permits unauthenticated XSS
Email Essentials through 6.0.6 allows an unauthenticated attacker to inject script into affected output. The script executes when a victim interacts with that output and can act within the victim's browser session.
6.0.7
CVE7.1
NVDPending