Newsletter – Send awesome emails from WordPress <= 9.3.3 - Unauthenticated Stored Cross-Site Scripting
high
The Newsletter – Send awesome emails from WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and including, 9.3.3. This is due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in p...
- CVSS:
- 7.2
- Affected:
- up to 9.3.3
- Fixed in:
- 9.3.4
- Disclosed:
- Aug 19, 2026
CVE-2026-66596 on NVD →
Newsletter – Send awesome emails from WordPress <= 9.1.0 - Cross-Site Request Forgery to Newsletter Unsubscription
medium
The Newsletter – Send awesome emails from WordPress plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 9.1.0. This is due to missing or incorrect nonce validation on the hook_newsletter_action() function. This makes it possible for unauthenticated attackers to unsubsc...
- CVSS:
- 4.3
- Affected:
- up to 9.1.0
- Fixed in:
- 9.1.1
- Disclosed:
- Jan 19, 2026
CVE-2026-1051 on NVD →
Newsletter – Send awesome emails from WordPress [newsletter] <= 9.0.9 (unfixed)
unknown
[en] Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Stefano Lissa Newsletter newsletter allows Blind SQL Injection.This issue affects Newsletter: from n/a through <= 9.0.9.
- Affected:
- up to 9.0.9
- Fix:
- No patched version reported
- Disclosed:
- Dec 16, 2025
CVE-2025-67999 on NVD →
Newsletter <= 9.0.9 - Authenticated (Administrator+) SQL Injection
medium
The Newsletter plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 9.0.9 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with administrator-level access and abo...
- CVSS:
- 4.9
- Affected:
- up to 9.0.9
- Fixed in:
- 9.1.0
- Disclosed:
- Dec 15, 2025
CVE-2025-67999 on NVD →
Newsletter <= 8.8.4 - Authenticated (Administrator+) Stored Cross-Site Scripting
medium
The Newsletter – Send awesome emails from WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 8.8.4 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level pe...
- CVSS:
- 5.5
- Affected:
- up to 8.8.4
- Fixed in:
- 8.8.5
- Disclosed:
- May 19, 2025
CVE-2025-3581 on NVD →
Newsletter <= 8.8.4 - Authenticated (Administrator+) Stored Cross-Site Scripting
medium
The Newsletter – Send awesome emails from WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 8.8.4 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level pe...
- CVSS:
- 4.4
- Affected:
- up to 8.8.4
- Fixed in:
- 8.8.5
- Disclosed:
- May 19, 2025
CVE-2025-3582 on NVD →
Newsletter <= 8.8.1 - Authenticated (Admin+) Stored Cross-Site Scripting
medium
The Newsletter – Send awesome emails from WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 8.8.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level pe...
- CVSS:
- 4.4
- Affected:
- up to 8.8.1
- Fixed in:
- 8.8.2
- Disclosed:
- May 13, 2025
CVE-2025-3584 on NVD →
Newsletter <= 8.7.0 - Authenticated (Admin+) Stored Cross-Site Scripting
medium
The Newsletter plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the preheader_text value in versions up to, and including, 8.7.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers with administrative level permissions and above to inject a...
- CVSS:
- 4.4
- Affected:
- up to 8.7.0
- Fixed in:
- 8.7.1
- Disclosed:
- Apr 14, 2025
CVE-2025-3583 on NVD →
Newsletter – Send awesome emails from WordPress [newsletter] < 8.3.5
unknown
[en] The Newsletter plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'np1' parameter in all versions up to, and including, 8.3.4 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will ex...
- Affected:
- up to 8.3.5
- Fixed in:
- 8.3.5
- Disclosed:
- Jun 5, 2024
CVE-2024-5317 on NVD →
Newsletter <= 8.3.4 - Unauthenticated Stored Cross-Site Scripting via np1
medium
The Newsletter plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'np1' parameter in all versions up to, and including, 8.3.4 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute...
- CVSS:
- 6.4
- Affected:
- up to 8.3.4
- Fixed in:
- 8.3.5
- Disclosed:
- Jun 4, 2024
CVE-2024-5317 on NVD →
Newsletter – Send awesome emails from WordPress [newsletter] < 8.2.1
unknown
[en] Authentication Bypass by Spoofing vulnerability in Stefano Lissa & The Newsletter Team Newsletter allows Functionality Bypass.This issue affects Newsletter: from n/a through 8.2.0.
- Affected:
- up to 8.2.1
- Fixed in:
- 8.2.1
- Disclosed:
- May 17, 2024
CVE-2024-30522 on NVD →
Newsletter – Send awesome emails from WordPress [newsletter] < 8.0.7
unknown
[en] Cross-Site Request Forgery (CSRF) vulnerability in Stefano Lissa & The Newsletter Team Newsletter.This issue affects Newsletter: from n/a through 8.0.6.
- Affected:
- up to 8.0.7
- Fixed in:
- 8.0.7
- Disclosed:
- Apr 15, 2024
CVE-2024-31434 on NVD →
Newsletter <= 8.0.6 - Cross-Site Request Forgery
medium
The Newsletter plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 8.0.6. This is due to missing or incorrect nonce validation in the main/welcome.php file. This makes it possible for unauthenticated attackers to trigger test emails via a forged request granted they can tr...
- CVSS:
- 4.3
- Affected:
- up to 8.0.6
- Fixed in:
- 8.0.7
- Disclosed:
- Apr 10, 2024
CVE-2024-31434 on NVD →
Newsletter <= 8.2.0 - IP Spoofing
medium
The Newsletter – Send awesome emails from WordPress plugin for WordPress is vulnerable to IP Address Spoofing in all versions up to, and including, 8.2.0 due to insufficient IP address validation. This makes it possible for unauthenticated attackers to spoof their IP address and bypass the blocklist.
- CVSS:
- 5.3
- Affected:
- up to 8.2.0
- Fixed in:
- 8.2.1
- Disclosed:
- Mar 28, 2024
CVE-2024-30522 on NVD →
Newsletter <= 8.0.6 - Cross-Site Request Forgery
medium
The Newsletter – Send awesome emails from WordPress plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 8.0.6. This is due to missing or incorrect nonce validation in the main/welcome.php file. This makes it possible for unauthenticated attackers to modify the plugin's...
- CVSS:
- 4.7
- Affected:
- up to 8.0.6
- Fixed in:
- 8.0.7
- Disclosed:
- Jan 10, 2024
Newsletter – Send awesome emails from WordPress [newsletter] < 8.0.7
unknown
The Newsletter – Send awesome emails from WordPress plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 8.0.6. This is due to missing or incorrect nonce validation in the main/welcome.php file. This makes it possible for unauthenticated attackers to modify the plugin's...
- Affected:
- up to 8.0.7
- Fixed in:
- 8.0.7
- Disclosed:
- Jan 10, 2024
Newsletter – Send awesome emails from WordPress [newsletter] < 7.9.0
unknown
[en] The Newsletter plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'newsletter_form' shortcode in versions up to, and including, 7.8.9 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers with contributor-le...
- Affected:
- up to 7.9.0
- Fixed in:
- 7.9.0
- Disclosed:
- Sep 7, 2023
CVE-2023-4772 on NVD →
Newsletter <= 7.8.9 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode
medium
The Newsletter plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'newsletter_form' shortcode in versions up to, and including, 7.8.9 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers with contributor-level a...
- CVSS:
- 6.4
- Affected:
- up to 7.8.9
- Fixed in:
- 7.9.0
- Disclosed:
- Aug 17, 2023
CVE-2023-4772 on NVD →
Newsletter – Send awesome emails from WordPress [newsletter] < 7.6.9
unknown
[en] Cross-site scripting vulnerability in Newsletter versions prior to 7.6.9 allows a remote unauthenticated attacker to inject an arbitrary script.
- Affected:
- up to 7.6.9
- Fixed in:
- 7.6.9
- Disclosed:
- May 23, 2023
CVE-2023-27922 on NVD →
Newsletter – Send awesome emails from WordPress [newsletter] < 7.6.9
unknown
Update the WordPress Email Newsletter plugin to the latest available version (at least 7.6.9).
Unknown discovered and reported this Cross Site Scripting (XSS) vulnerability in WordPress Newsletter Plugin. This could allow a malicious actor to inject malicious scripts, such as redirects, advertisements, and other HTML p...
- Affected:
- up to 7.6.9
- Fixed in:
- 7.6.9
- Disclosed:
- Mar 29, 2023
Newsletter <= 7.6.8 - Reflected Cross-Site Scripting
medium
The Newsletter plugin for WordPress may be vulnerable to Reflected Cross-Site Scripting via the $_SERVER['REQUEST_URI'] parameter in versions up to, and including, 7.6.8 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pa...
- CVSS:
- 4.7
- Affected:
- up to 7.6.8
- Fixed in:
- 7.6.9
- Disclosed:
- Mar 27, 2023
CVE-2023-27922 on NVD →
Newsletter – Send awesome emails from WordPress [newsletter] < 7.6.9
unknown
The Newsletter plugin for WordPress may be vulnerable to Reflected Cross-Site Scripting via the $_SERVER['REQUEST_URI'] parameter in versions up to, and including, 7.6.8 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pa...
- Affected:
- up to 7.6.9
- Fixed in:
- 7.6.9
- Disclosed:
- Mar 27, 2023
Newsletter – Send awesome emails from WordPress [newsletter] < 7.4.6
unknown
[en] The Newsletter WordPress plugin before 7.4.6 does not escape and sanitise the preheader_text setting, which could allow high privilege users to perform Stored Cross-Site Scripting attacks when the unfilteredhtml is disallowed
- Affected:
- up to 7.4.6
- Fixed in:
- 7.4.6
- Disclosed:
- Jun 20, 2022
CVE-2022-1889 on NVD →
Newsletter – Send awesome emails from WordPress [newsletter] < 7.4.5
unknown
[en] The Newsletter WordPress plugin before 7.4.5 does not sanitize and escape the $_SERVER['REQUEST_URI'] before echoing it back in admin pages. Although this uses addslashes, and most modern browsers automatically URLEncode requests, this is still vulnerable to Reflected XSS in older browsers such as Internet Explore...
- Affected:
- up to 7.4.5
- Fixed in:
- 7.4.5
- Disclosed:
- Jun 13, 2022
CVE-2022-1756 on NVD →
Newsletter <= 7.4.5 - Authenticated (Admin+) Stored Cross-Site Scripting
medium
The Newsletter plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the preheader_text value in versions up to, and including, 7.4.5 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers with administrative level permissions and above to inject a...
- CVSS:
- 5.5
- Affected:
- up to 7.4.6
- Fixed in:
- 7.4.6
- Disclosed:
- May 30, 2022
CVE-2022-1889 on NVD →
Newsletter – Send awesome emails from WordPress <= 7.4.4 - Reflected Cross-Site Scripting
medium
The Newsletter WordPress plugin before 7.4.5 does not sanitize and escape the $_SERVER['REQUEST_URI'] before echoing it back in admin pages. Although this uses addslashes, and most modern browsers automatically URLEncode requests, this is still vulnerable to Reflected XSS in older browsers such as Internet Explorer 9 o...
- CVSS:
- 6.1
- Affected:
- up to 7.4.4
- Fixed in:
- 7.4.5
- Disclosed:
- May 23, 2022
CVE-2022-1756 on NVD →
Newsletter – Send awesome emails from WordPress [newsletter] < 7.4.5
unknown
Reflected Cross-Site Scripting (XSS) vulnerability discovered in WordPress Newsletter plugin (versions <= 7.4.4).
Update the WordPress Newsletter plugin to the latest available version (at least 7.4.5).
- Affected:
- up to 7.4.5
- Fixed in:
- 7.4.5
- Disclosed:
- May 17, 2022
Newsletter – Send awesome emails from WordPress [newsletter] < 6.5.4
unknown
CSV Injection vulnerability discovered by Fortinet in WordPress Newsletter plugin (versions <= 6.5.3).
- Affected:
- up to 6.5.4
- Fixed in:
- 6.5.4
- Disclosed:
- Mar 16, 2021
Newsletter – Send awesome emails from WordPress [newsletter] < 6.8.2
unknown
[en] A Reflected Authenticated Cross-Site Scripting (XSS) vulnerability in the Newsletter plugin before 6.8.2 for WordPress allows remote attackers to trick a victim into submitting a tnpc_render AJAX request containing either JavaScript in an options parameter, or a base64-encoded JSON string containing JavaScript in...
- Affected:
- up to 6.8.2
- Fixed in:
- 6.8.2
- Disclosed:
- Jan 1, 2021
CVE-2020-35933 on NVD →
Newsletter – Send awesome emails from WordPress [newsletter] < 6.8.2
unknown
[en] Insecure Deserialization in the Newsletter plugin before 6.8.2 for WordPress allows authenticated remote attackers with minimal privileges (such as subscribers) to use the tpnc_render AJAX action to inject arbitrary PHP objects via the options[inline_edits] parameter. NOTE: exploitability depends on PHP objects th...
- Affected:
- up to 6.8.2
- Fixed in:
- 6.8.2
- Disclosed:
- Jan 1, 2021
CVE-2020-35932 on NVD →
Newsletter <= 6.8.1 - Reflected Cross-Site Scripting
medium
A Reflected Authenticated Cross-Site Scripting (XSS) vulnerability in the Newsletter plugin before 6.8.2 for WordPress allows remote attackers to trick a victim into submitting a tnpc_render AJAX request containing either JavaScript in an options parameter, or a base64-encoded JSON string containing JavaScript in the e...
- CVSS:
- 6.5
- Affected:
- up to 6.8.2
- Fixed in:
- 6.8.2
- Disclosed:
- Aug 3, 2020
CVE-2020-35933 on NVD →
Newsletter <= 6.8.1 - Authenticated PHP Object Injection
high
Insecure Deserialization in the Newsletter plugin before 6.8.2 for WordPress allows authenticated remote attackers with minimal privileges (such as subscribers) to use the tpnc_render AJAX action to inject arbitrary PHP objects via the options[inline_edits] parameter. NOTE: exploitability depends on PHP objects that mi...
- CVSS:
- 7.5
- Affected:
- up to 6.8.2
- Fixed in:
- 6.8.2
- Disclosed:
- Aug 2, 2020
CVE-2020-35932 on NVD →
Newsletter <= 6.7.6 - Stored Cross-Site Scripting
high
The Newsletter plugin for WordPress is vulnerable to Stored Cross-Site Scripting via multiple parameters in versions up to, and including, 6.7.6 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers to inject arbitrary web scripts in pages that will execute whene...
- CVSS:
- 8.3
- Affected:
- up to 6.7.6
- Fixed in:
- 6.7.7
- Disclosed:
- Jul 12, 2020
Newsletter – Send awesome emails from WordPress [newsletter] < 6.7.7
unknown
The Newsletter plugin for WordPress is vulnerable to Stored Cross-Site Scripting via multiple parameters in versions up to, and including, 6.7.6 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers to inject arbitrary web scripts in pages that will execute whene...
- Affected:
- up to 6.7.7
- Fixed in:
- 6.7.7
- Disclosed:
- Jul 12, 2020
Newsletter – Send awesome emails from WordPress [newsletter] < 6.7.7
unknown
Authenticated Stored Cross-Site Scripting (XSS) vulnerability discovered by Chevon Phillip in WordPress Newsletter plugin (versions <= 6.7.6).
- Affected:
- up to 6.7.7
- Fixed in:
- 6.7.7
- Disclosed:
- Jul 12, 2020
Newsletter <= 6.5.3 - CSV Injection
medium
The Newsletter plugin for WordPress is vulnerable to CSV Injection in versions up to, and including, 6.5.3 by the use of Microsoft Excel DDE function, or to leak data via maliciously injected hyperlinks. This allows non-privileged attackers to embed untrusted input into exported CSV files, which can result in code exec...
- CVSS:
- 5.5
- Affected:
- up to 6.5.3
- Fixed in:
- 6.5.4
- Disclosed:
- Mar 16, 2020
Newsletter – Send awesome emails from WordPress [newsletter] < 6.5.4
unknown
The Newsletter plugin for WordPress is vulnerable to CSV Injection in versions up to, and including, 6.5.3 by the use of Microsoft Excel DDE function, or to leak data via maliciously injected hyperlinks. This allows non-privileged attackers to embed untrusted input into exported CSV files, which can result in code exec...
- Affected:
- up to 6.5.4
- Fixed in:
- 6.5.4
- Disclosed:
- Mar 16, 2020
Newsletter – Send awesome emails from WordPress [newsletter] < 3.0.9
unknown
Because of this vulnerability, remote authenticated users can execute arbitrary SQL commands.
Upgrade the plugin.
- Affected:
- up to 3.0.9
- Fixed in:
- 3.0.9
- Disclosed:
- Oct 18, 2015
Newsletter – Send awesome emails from WordPress [newsletter] < 3.2.7
unknown
Because of this vulnerability, the attackers can inject arbitrary JavaScript or HTML code.
Update the plugin.
- Affected:
- up to 3.2.7
- Fixed in:
- 3.2.7
- Disclosed:
- May 15, 2015
Newsletter <= 3.8.2 - Open Redirect
medium
The Newsletter plugin is susceptible to an Open Redirect vulnerability. This issue is due to the fact user input it taken, and trusted, without validation. This user input is used when tracking link clicks, via the ‘newsletter/statistics/link.php’ script. User input is Base64 encoded, and split on the ‘;’ character, th...
- CVSS:
- 4.3
- Affected:
- up to 3.8.2
- Fixed in:
- 3.8.3
- Disclosed:
- Mar 30, 2015
Newsletter – Send awesome emails from WordPress [newsletter] < 3.8.3
unknown
This plugin is prone to an open redirection vulnerability.
Update the plugin.
- Affected:
- up to 3.8.3
- Fixed in:
- 3.8.3
- Disclosed:
- Mar 30, 2015
Newsletter – Send awesome emails from WordPress [newsletter] < 3.8.3
unknown
The Newsletter plugin is susceptible to an Open Redirect vulnerability. This issue is due to the fact user input it taken, and trusted, without validation. This user input is used when tracking link clicks, via the ‘newsletter/statistics/link.php’ script. User input is Base64 encoded, and split on the ‘;’ character, th...
- Affected:
- up to 3.8.3
- Fixed in:
- 3.8.3
- Disclosed:
- Mar 30, 2015
Newsletter <= 3.2.6 - Reflected Cross-Site Scripting
medium
The Newsletter plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘alert’ parameter in the 'page.php' file in versions up to, and including, 3.2.6 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in...
- CVSS:
- 6.1
- Affected:
- up to 3.2.6
- Fixed in:
- 3.2.7
- Disclosed:
- May 14, 2013
Newsletter – Send awesome emails from WordPress [newsletter] < 3.2.7
unknown
The Newsletter plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘alert’ parameter in the 'page.php' file in versions up to, and including, 3.2.6 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in...
- Affected:
- up to 3.2.7
- Fixed in:
- 3.2.7
- Disclosed:
- May 14, 2013
Newsletter – Send awesome emails from WordPress [newsletter] < 3.0.9
unknown
The Newsletter WordPress plugin was affected by a SQL Injection security vulnerability.
- Affected:
- up to 3.0.9
- Fixed in:
- 3.0.9
Newsletter – Send awesome emails from WordPress [newsletter] < 3.2.7
unknown
The Newsletter WordPress plugin was affected by a Cross-Site Scripting (XSS) security vulnerability.
- Affected:
- up to 3.2.7
- Fixed in:
- 3.2.7
Newsletter – Send awesome emails from WordPress [newsletter] < 3.8.3
unknown
The Newsletter plugin is susceptible to an Open Redirect vulnerability. This issue is due to the fact user input it taken, and trusted, without validation.
This user input is used when tracking link clicks, via the ‘newsletter/statistics/link.php’ script. User input is Base64 encoded, and split on the &l...
- Affected:
- up to 3.8.3
- Fixed in:
- 3.8.3
Newsletter – Send awesome emails from WordPress [newsletter] < 6.5.4
unknown
A CSV Injection vulnerability was discovered in Wordpress Newsletter plugin. It allows a user with low level privileges or no privileges to inject a command in subscription form that will be included in the exported CSV file, leading to possible code execution.
- Affected:
- up to 6.5.4
- Fixed in:
- 6.5.4
Newsletter – Send awesome emails from WordPress [newsletter] < 8.7.1
unknown
- Affected:
- up to 8.7.1
- Fixed in:
- 8.7.1
CVE-2025-3583 on NVD →
Newsletter – Send awesome emails from WordPress [newsletter] < 8.8.2
unknown
- Affected:
- up to 8.8.2
- Fixed in:
- 8.8.2
CVE-2025-3584 on NVD →
Newsletter – Send awesome emails from WordPress [newsletter] < 6.7.7
unknown
An Authenticated Stored Cross-Site Scripting (XSS) was discovered within the Company Info "Motto" field. When creating a new newsletter using an empty template with the header module, the XSS would execute.
This was later fixed in version: 6.7.7
- Affected:
- up to 6.7.7
- Fixed in:
- 6.7.7