CVE-2026-1266 | Postalicious Plugin up to 3.0.1 on WordPress Setting cross site scripting (EUVD-2026-4544)
A vulnerability classified as problematic has been found in Postalicious Plugin up to 3.0.1 on WordPress. This impacts an unknown function of the component Setting Handler. Performing a manipulation results in cross site scripting.
This vulnerability is reported as CVE-2026-1266. The attack is possible to be carried out remotely. No exploit exists.