XSS attacks in email marketing typically occur when an attacker sends a malicious email containing harmful scripts. If the email client or webmail service does not properly sanitize the content, the script can execute when the recipient opens the email. This can lead to data theft, unauthorized actions, or even the installation of malware.