CVE-2026-8089: Unknown Wemail: Email Marketing, Email Automation, Newsletters, Subscribers & Email Optins For Woocommerce

High severity, CVSS 7.1. EPSS: 0.3% chance of exploitation in the next 30 days.

The weMail: Email Marketing, Email Automation, Newsletters, Subscribers & Email Optins for WooCommerce WordPress plugin before 2.1.3 does not properly escape a user-supplied parameter before reflecting it into an HTML attribute on a non-nonce-protected AJAX response, allowing unauthenticated attackers to deliver Reflected Cross-Site Scripting against any authenticated user (including administrators) via a crafted URL.

Affected products

  • Unknown Wemail: Email Marketing, Email Automation, Newsletters, Subscribers & Email Optins For Woocommerce: before 2.1.3 (fixed in 2.1.3)

Published 2026-06-17. Last modified 2026-06-17.