CVE-2026-13362 | SendPulse Email Marketing Newsletter Plugin up to 2.2.5 on WordPress Shortcode _sp_form_code cross site scripting

SecurityVulns

A vulnerability described as problematic has been identified in SendPulse Email Marketing Newsletter Plugin up to 2.2.5 on WordPress. Affected by this issue is some unknown functionality of the component Shortcode Handler. Such manipulation of the argument _sp_form_code leads to cross site scripting.

This vulnerability is documented as CVE-2026-13362. The attack can be executed remotely. There is not any exploit available.VulDB Recent EntriesRead More