← WordPress Vulnerabilities
WordPress security by component

MailArchiver

MailArchiver is a WordPress component with 3 published CVE records in this archive. The latest tracked vulnerability was published Mar 07, 2026; the highest CVE/CNA score is 7.2.

Plugin slug: mailarchiver

CVE-2026-2721: MailArchiver: Cross-site scripting

MailArchiver is affected by cross-site scripting. Exploitation requires an authenticated WordPress account. Injected script can execute in the affected site's origin when the vulnerable output is viewed.

PublishedMar 07, 2026
Safe version guidanceSee mitigation notes
Safe version
Mar 07, 2026 CVE-2026-2721
MailArchiver: Cross-site scripting
MailArchiver is affected by cross-site scripting. Exploitation requires an authenticated WordPress account. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE4.8
NVDPending
Feb 27, 2026 CVE-2026-2831
MailArchiver: SQL injection
MailArchiver is affected by SQL injection. Exploitation requires at least administrator-level access. A successful request can alter database queries and expose or modify WordPress data.
See mitigation notes
CVE4.9
NVDPending
Aug 30, 2023 CVE-2023-3136
MailArchiver: Cross-site scripting
MailArchiver is affected by cross-site scripting. The vulnerable path is reachable without authentication. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE7.2
NVD6.1