What is CVE-2026-16636?
CVE-2026-16636 is a Stored Cross-Site Scripting (XSS) vulnerability in the FluentSMTP WordPress plugin. The flaw exists in the Email Logs functionality due to insufficient input sanitization of the Recipient Display Name (to.name) parameter. Users should update the plugin to the latest version immediately or follow vendor guidance for mitigation.
Azərbaycanca: CVE-2026-16636, FluentSMTP WordPress plaginində Saxlanılan Cross-Site Scripting (XSS) boşluğudur. Zəiflik Email Logs funksiyasında Recipient Display Name (to.name) parametrinin kifayət qədər təmizlənməməsi səbəbindən baş verir. İstifadəçilər plaqini dərhal son versiyaya yeniləməli və ya müvəqqəti tədbirlər üçün vendorun təlimatlarını izləməlidir.
Related CVEs
link basis: same weakness class CWE-79
FAQ1
Where does the CVE-2026-16636 vulnerability occur in the FluentSMTP plugin?
The Stored XSS vulnerability exists in the Email Logs functionality of FluentSMTP due to insufficient input sanitization of the Recipient Display Name (to.name) parameter.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.