plugin

Newsletter Vulnerabilities

51 known security issues reported for the Newsletter WordPress plugin. Most recent disclosed Aug 19, 2026.

3 high 18 medium

Running Newsletter on your site? Check whether your installed version is affected.

Scan your site free

Newsletter – Send awesome emails from WordPress <= 9.3.3 - Unauthenticated Stored Cross-Site Scripting

high

The Newsletter – Send awesome emails from WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and including, 9.3.3. This is due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in p...

CVSS:
7.2
Affected:
up to 9.3.3
Fixed in:
9.3.4
Disclosed:
Aug 19, 2026

CVE-2026-66596 on NVD →

Newsletter – Send awesome emails from WordPress <= 9.1.0 - Cross-Site Request Forgery to Newsletter Unsubscription

medium

The Newsletter – Send awesome emails from WordPress plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 9.1.0. This is due to missing or incorrect nonce validation on the hook_newsletter_action() function. This makes it possible for unauthenticated attackers to unsubsc...

CVSS:
4.3
Affected:
up to 9.1.0
Fixed in:
9.1.1
Disclosed:
Jan 19, 2026

CVE-2026-1051 on NVD →

Newsletter &#8211; Send awesome emails from WordPress [newsletter] <= 9.0.9 (unfixed)

unknown

[en] Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Stefano Lissa Newsletter newsletter allows Blind SQL Injection.This issue affects Newsletter: from n/a through <= 9.0.9.

Affected:
up to 9.0.9
Fix:
No patched version reported
Disclosed:
Dec 16, 2025

CVE-2025-67999 on NVD →

Newsletter <= 9.0.9 - Authenticated (Administrator+) SQL Injection

medium

The Newsletter plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 9.0.9 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with administrator-level access and abo...

CVSS:
4.9
Affected:
up to 9.0.9
Fixed in:
9.1.0
Disclosed:
Dec 15, 2025

CVE-2025-67999 on NVD →

Newsletter <= 8.8.4 - Authenticated (Administrator+) Stored Cross-Site Scripting

medium

The Newsletter – Send awesome emails from WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 8.8.4 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level pe...

CVSS:
5.5
Affected:
up to 8.8.4
Fixed in:
8.8.5
Disclosed:
May 19, 2025

CVE-2025-3581 on NVD →

Newsletter <= 8.8.4 - Authenticated (Administrator+) Stored Cross-Site Scripting

medium

The Newsletter – Send awesome emails from WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 8.8.4 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level pe...

CVSS:
4.4
Affected:
up to 8.8.4
Fixed in:
8.8.5
Disclosed:
May 19, 2025

CVE-2025-3582 on NVD →

Newsletter <= 8.8.1 - Authenticated (Admin+) Stored Cross-Site Scripting

medium

The Newsletter – Send awesome emails from WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 8.8.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level pe...

CVSS:
4.4
Affected:
up to 8.8.1
Fixed in:
8.8.2
Disclosed:
May 13, 2025

CVE-2025-3584 on NVD →

Newsletter <= 8.7.0 - Authenticated (Admin+) Stored Cross-Site Scripting

medium

The Newsletter plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the preheader_text value in versions up to, and including, 8.7.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers with administrative level permissions and above to inject a...

CVSS:
4.4
Affected:
up to 8.7.0
Fixed in:
8.7.1
Disclosed:
Apr 14, 2025

CVE-2025-3583 on NVD →

Newsletter &#8211; Send awesome emails from WordPress [newsletter] < 8.3.5

unknown

[en] The Newsletter plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'np1' parameter in all versions up to, and including, 8.3.4 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will ex...

Affected:
up to 8.3.5
Fixed in:
8.3.5
Disclosed:
Jun 5, 2024

CVE-2024-5317 on NVD →

Newsletter <= 8.3.4 - Unauthenticated Stored Cross-Site Scripting via np1

medium

The Newsletter plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'np1' parameter in all versions up to, and including, 8.3.4 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute...

CVSS:
6.4
Affected:
up to 8.3.4
Fixed in:
8.3.5
Disclosed:
Jun 4, 2024

CVE-2024-5317 on NVD →

Newsletter &#8211; Send awesome emails from WordPress [newsletter] < 8.2.1

unknown

[en] Authentication Bypass by Spoofing vulnerability in Stefano Lissa & The Newsletter Team Newsletter allows Functionality Bypass.This issue affects Newsletter: from n/a through 8.2.0.

Affected:
up to 8.2.1
Fixed in:
8.2.1
Disclosed:
May 17, 2024

CVE-2024-30522 on NVD →

Newsletter &#8211; Send awesome emails from WordPress [newsletter] < 8.0.7

unknown

[en] Cross-Site Request Forgery (CSRF) vulnerability in Stefano Lissa & The Newsletter Team Newsletter.This issue affects Newsletter: from n/a through 8.0.6.

Affected:
up to 8.0.7
Fixed in:
8.0.7
Disclosed:
Apr 15, 2024

CVE-2024-31434 on NVD →

Newsletter <= 8.0.6 - Cross-Site Request Forgery

medium

The Newsletter plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 8.0.6. This is due to missing or incorrect nonce validation in the main/welcome.php file. This makes it possible for unauthenticated attackers to trigger test emails via a forged request granted they can tr...

CVSS:
4.3
Affected:
up to 8.0.6
Fixed in:
8.0.7
Disclosed:
Apr 10, 2024

CVE-2024-31434 on NVD →

Newsletter <= 8.2.0 - IP Spoofing

medium

The Newsletter – Send awesome emails from WordPress plugin for WordPress is vulnerable to IP Address Spoofing in all versions up to, and including, 8.2.0 due to insufficient IP address validation. This makes it possible for unauthenticated attackers to spoof their IP address and bypass the blocklist.

CVSS:
5.3
Affected:
up to 8.2.0
Fixed in:
8.2.1
Disclosed:
Mar 28, 2024

CVE-2024-30522 on NVD →

Newsletter <= 8.0.6 - Cross-Site Request Forgery

medium

The Newsletter – Send awesome emails from WordPress plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 8.0.6. This is due to missing or incorrect nonce validation in the main/welcome.php file. This makes it possible for unauthenticated attackers to modify the plugin's...

CVSS:
4.7
Affected:
up to 8.0.6
Fixed in:
8.0.7
Disclosed:
Jan 10, 2024

Newsletter &#8211; Send awesome emails from WordPress [newsletter] < 8.0.7

unknown

The Newsletter – Send awesome emails from WordPress plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 8.0.6. This is due to missing or incorrect nonce validation in the main/welcome.php file. This makes it possible for unauthenticated attackers to modify the plugin's...

Affected:
up to 8.0.7
Fixed in:
8.0.7
Disclosed:
Jan 10, 2024

Newsletter &#8211; Send awesome emails from WordPress [newsletter] < 7.9.0

unknown

[en] The Newsletter plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'newsletter_form' shortcode in versions up to, and including, 7.8.9 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers with contributor-le...

Affected:
up to 7.9.0
Fixed in:
7.9.0
Disclosed:
Sep 7, 2023

CVE-2023-4772 on NVD →

Newsletter <= 7.8.9 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode

medium

The Newsletter plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'newsletter_form' shortcode in versions up to, and including, 7.8.9 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers with contributor-level a...

CVSS:
6.4
Affected:
up to 7.8.9
Fixed in:
7.9.0
Disclosed:
Aug 17, 2023

CVE-2023-4772 on NVD →

Newsletter &#8211; Send awesome emails from WordPress [newsletter] < 7.6.9

unknown

[en] Cross-site scripting vulnerability in Newsletter versions prior to 7.6.9 allows a remote unauthenticated attacker to inject an arbitrary script.

Affected:
up to 7.6.9
Fixed in:
7.6.9
Disclosed:
May 23, 2023

CVE-2023-27922 on NVD →

Newsletter &#8211; Send awesome emails from WordPress [newsletter] < 7.6.9

unknown

Update the WordPress Email Newsletter plugin to the latest available version (at least 7.6.9). Unknown discovered and reported this Cross Site Scripting (XSS) vulnerability in WordPress Newsletter Plugin. This could allow a malicious actor to inject malicious scripts, such as redirects, advertisements, and other HTML p...

Affected:
up to 7.6.9
Fixed in:
7.6.9
Disclosed:
Mar 29, 2023

Newsletter <= 7.6.8 - Reflected Cross-Site Scripting

medium

The Newsletter plugin for WordPress may be vulnerable to Reflected Cross-Site Scripting via the $_SERVER['REQUEST_URI'] parameter in versions up to, and including, 7.6.8 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pa...

CVSS:
4.7
Affected:
up to 7.6.8
Fixed in:
7.6.9
Disclosed:
Mar 27, 2023

CVE-2023-27922 on NVD →

Newsletter &#8211; Send awesome emails from WordPress [newsletter] < 7.6.9

unknown

The Newsletter plugin for WordPress may be vulnerable to Reflected Cross-Site Scripting via the $_SERVER['REQUEST_URI'] parameter in versions up to, and including, 7.6.8 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pa...

Affected:
up to 7.6.9
Fixed in:
7.6.9
Disclosed:
Mar 27, 2023

Newsletter &#8211; Send awesome emails from WordPress [newsletter] < 7.4.6

unknown

[en] The Newsletter WordPress plugin before 7.4.6 does not escape and sanitise the preheader_text setting, which could allow high privilege users to perform Stored Cross-Site Scripting attacks when the unfilteredhtml is disallowed

Affected:
up to 7.4.6
Fixed in:
7.4.6
Disclosed:
Jun 20, 2022

CVE-2022-1889 on NVD →

Newsletter &#8211; Send awesome emails from WordPress [newsletter] < 7.4.5

unknown

[en] The Newsletter WordPress plugin before 7.4.5 does not sanitize and escape the $_SERVER['REQUEST_URI'] before echoing it back in admin pages. Although this uses addslashes, and most modern browsers automatically URLEncode requests, this is still vulnerable to Reflected XSS in older browsers such as Internet Explore...

Affected:
up to 7.4.5
Fixed in:
7.4.5
Disclosed:
Jun 13, 2022

CVE-2022-1756 on NVD →

Newsletter <= 7.4.5 - Authenticated (Admin+) Stored Cross-Site Scripting

medium

The Newsletter plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the preheader_text value in versions up to, and including, 7.4.5 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers with administrative level permissions and above to inject a...

CVSS:
5.5
Affected:
up to 7.4.6
Fixed in:
7.4.6
Disclosed:
May 30, 2022

CVE-2022-1889 on NVD →

Newsletter – Send awesome emails from WordPress <= 7.4.4 - Reflected Cross-Site Scripting

medium

The Newsletter WordPress plugin before 7.4.5 does not sanitize and escape the $_SERVER['REQUEST_URI'] before echoing it back in admin pages. Although this uses addslashes, and most modern browsers automatically URLEncode requests, this is still vulnerable to Reflected XSS in older browsers such as Internet Explorer 9 o...

CVSS:
6.1
Affected:
up to 7.4.4
Fixed in:
7.4.5
Disclosed:
May 23, 2022

CVE-2022-1756 on NVD →

Newsletter &#8211; Send awesome emails from WordPress [newsletter] < 7.4.5

unknown

Reflected Cross-Site Scripting (XSS) vulnerability discovered in WordPress Newsletter plugin (versions <= 7.4.4). Update the WordPress Newsletter plugin to the latest available version (at least 7.4.5).

Affected:
up to 7.4.5
Fixed in:
7.4.5
Disclosed:
May 17, 2022

Newsletter &#8211; Send awesome emails from WordPress [newsletter] < 6.5.4

unknown

CSV Injection vulnerability discovered by Fortinet in WordPress Newsletter plugin (versions <= 6.5.3).

Affected:
up to 6.5.4
Fixed in:
6.5.4
Disclosed:
Mar 16, 2021

Newsletter &#8211; Send awesome emails from WordPress [newsletter] < 6.8.2

unknown

[en] A Reflected Authenticated Cross-Site Scripting (XSS) vulnerability in the Newsletter plugin before 6.8.2 for WordPress allows remote attackers to trick a victim into submitting a tnpc_render AJAX request containing either JavaScript in an options parameter, or a base64-encoded JSON string containing JavaScript in...

Affected:
up to 6.8.2
Fixed in:
6.8.2
Disclosed:
Jan 1, 2021

CVE-2020-35933 on NVD →

Newsletter &#8211; Send awesome emails from WordPress [newsletter] < 6.8.2

unknown

[en] Insecure Deserialization in the Newsletter plugin before 6.8.2 for WordPress allows authenticated remote attackers with minimal privileges (such as subscribers) to use the tpnc_render AJAX action to inject arbitrary PHP objects via the options[inline_edits] parameter. NOTE: exploitability depends on PHP objects th...

Affected:
up to 6.8.2
Fixed in:
6.8.2
Disclosed:
Jan 1, 2021

CVE-2020-35932 on NVD →

Newsletter <= 6.8.1 - Reflected Cross-Site Scripting

medium

A Reflected Authenticated Cross-Site Scripting (XSS) vulnerability in the Newsletter plugin before 6.8.2 for WordPress allows remote attackers to trick a victim into submitting a tnpc_render AJAX request containing either JavaScript in an options parameter, or a base64-encoded JSON string containing JavaScript in the e...

CVSS:
6.5
Affected:
up to 6.8.2
Fixed in:
6.8.2
Disclosed:
Aug 3, 2020

CVE-2020-35933 on NVD →

Newsletter <= 6.8.1 - Authenticated PHP Object Injection

high

Insecure Deserialization in the Newsletter plugin before 6.8.2 for WordPress allows authenticated remote attackers with minimal privileges (such as subscribers) to use the tpnc_render AJAX action to inject arbitrary PHP objects via the options[inline_edits] parameter. NOTE: exploitability depends on PHP objects that mi...

CVSS:
7.5
Affected:
up to 6.8.2
Fixed in:
6.8.2
Disclosed:
Aug 2, 2020

CVE-2020-35932 on NVD →

Newsletter <= 6.7.6 - Stored Cross-Site Scripting

high

The Newsletter plugin for WordPress is vulnerable to Stored Cross-Site Scripting via multiple parameters in versions up to, and including, 6.7.6 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers to inject arbitrary web scripts in pages that will execute whene...

CVSS:
8.3
Affected:
up to 6.7.6
Fixed in:
6.7.7
Disclosed:
Jul 12, 2020

Newsletter &#8211; Send awesome emails from WordPress [newsletter] < 6.7.7

unknown

The Newsletter plugin for WordPress is vulnerable to Stored Cross-Site Scripting via multiple parameters in versions up to, and including, 6.7.6 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers to inject arbitrary web scripts in pages that will execute whene...

Affected:
up to 6.7.7
Fixed in:
6.7.7
Disclosed:
Jul 12, 2020

Newsletter &#8211; Send awesome emails from WordPress [newsletter] < 6.7.7

unknown

Authenticated Stored Cross-Site Scripting (XSS) vulnerability discovered by Chevon Phillip in WordPress Newsletter plugin (versions <= 6.7.6).

Affected:
up to 6.7.7
Fixed in:
6.7.7
Disclosed:
Jul 12, 2020

Newsletter <= 6.5.3 - CSV Injection

medium

The Newsletter plugin for WordPress is vulnerable to CSV Injection in versions up to, and including, 6.5.3 by the use of Microsoft Excel DDE function, or to leak data via maliciously injected hyperlinks. This allows non-privileged attackers to embed untrusted input into exported CSV files, which can result in code exec...

CVSS:
5.5
Affected:
up to 6.5.3
Fixed in:
6.5.4
Disclosed:
Mar 16, 2020

Newsletter &#8211; Send awesome emails from WordPress [newsletter] < 6.5.4

unknown

The Newsletter plugin for WordPress is vulnerable to CSV Injection in versions up to, and including, 6.5.3 by the use of Microsoft Excel DDE function, or to leak data via maliciously injected hyperlinks. This allows non-privileged attackers to embed untrusted input into exported CSV files, which can result in code exec...

Affected:
up to 6.5.4
Fixed in:
6.5.4
Disclosed:
Mar 16, 2020

Newsletter &#8211; Send awesome emails from WordPress [newsletter] < 3.0.9

unknown

Because of this vulnerability, remote authenticated users can execute arbitrary SQL commands. Upgrade the plugin.

Affected:
up to 3.0.9
Fixed in:
3.0.9
Disclosed:
Oct 18, 2015

Newsletter &#8211; Send awesome emails from WordPress [newsletter] < 3.2.7

unknown

Because of this vulnerability, the attackers can inject arbitrary JavaScript or HTML code. Update the plugin.

Affected:
up to 3.2.7
Fixed in:
3.2.7
Disclosed:
May 15, 2015

Newsletter <= 3.8.2 - Open Redirect

medium

The Newsletter plugin is susceptible to an Open Redirect vulnerability. This issue is due to the fact user input it taken, and trusted, without validation. This user input is used when tracking link clicks, via the ‘newsletter/statistics/link.php’ script. User input is Base64 encoded, and split on the ‘;’ character, th...

CVSS:
4.3
Affected:
up to 3.8.2
Fixed in:
3.8.3
Disclosed:
Mar 30, 2015

Newsletter &#8211; Send awesome emails from WordPress [newsletter] < 3.8.3

unknown

This plugin is prone to an open redirection vulnerability. Update the plugin.

Affected:
up to 3.8.3
Fixed in:
3.8.3
Disclosed:
Mar 30, 2015

Newsletter &#8211; Send awesome emails from WordPress [newsletter] < 3.8.3

unknown

The Newsletter plugin is susceptible to an Open Redirect vulnerability. This issue is due to the fact user input it taken, and trusted, without validation. This user input is used when tracking link clicks, via the ‘newsletter/statistics/link.php’ script. User input is Base64 encoded, and split on the ‘;’ character, th...

Affected:
up to 3.8.3
Fixed in:
3.8.3
Disclosed:
Mar 30, 2015

Newsletter <= 3.2.6 - Reflected Cross-Site Scripting

medium

The Newsletter plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘alert’ parameter in the 'page.php' file in versions up to, and including, 3.2.6 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in...

CVSS:
6.1
Affected:
up to 3.2.6
Fixed in:
3.2.7
Disclosed:
May 14, 2013

Newsletter &#8211; Send awesome emails from WordPress [newsletter] < 3.2.7

unknown

The Newsletter plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘alert’ parameter in the 'page.php' file in versions up to, and including, 3.2.6 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in...

Affected:
up to 3.2.7
Fixed in:
3.2.7
Disclosed:
May 14, 2013

Newsletter &#8211; Send awesome emails from WordPress [newsletter] < 3.0.9

unknown

The Newsletter WordPress plugin was affected by a SQL Injection security vulnerability.

Affected:
up to 3.0.9
Fixed in:
3.0.9

Newsletter &#8211; Send awesome emails from WordPress [newsletter] < 3.2.7

unknown

The Newsletter WordPress plugin was affected by a Cross-Site Scripting (XSS) security vulnerability.

Affected:
up to 3.2.7
Fixed in:
3.2.7

Newsletter &#8211; Send awesome emails from WordPress [newsletter] < 3.8.3

unknown

The Newsletter plugin is susceptible to an Open Redirect vulnerability. This issue is due to the fact user input it taken, and trusted, without validation. This user input is used when tracking link clicks, via the &lsquo;newsletter/statistics/link.php&rsquo; script. User input is Base64 encoded, and split on the &l...

Affected:
up to 3.8.3
Fixed in:
3.8.3

Newsletter &#8211; Send awesome emails from WordPress [newsletter] < 6.5.4

unknown

A CSV Injection vulnerability was discovered in Wordpress Newsletter plugin. It allows a user with low level privileges or no privileges to inject a command in subscription form that will be included in the exported CSV file, leading to possible code execution.

Affected:
up to 6.5.4
Fixed in:
6.5.4

Newsletter &#8211; Send awesome emails from WordPress [newsletter] < 8.7.1

unknown
Affected:
up to 8.7.1
Fixed in:
8.7.1

CVE-2025-3583 on NVD →

Newsletter &#8211; Send awesome emails from WordPress [newsletter] < 8.8.2

unknown
Affected:
up to 8.8.2
Fixed in:
8.8.2

CVE-2025-3584 on NVD →

Newsletter &#8211; Send awesome emails from WordPress [newsletter] < 6.7.7

unknown

An Authenticated Stored Cross-Site Scripting (XSS) was discovered within the Company Info &quot;Motto&quot; field. When creating a new newsletter using an empty template with the header module, the XSS would execute. This was later fixed in version: 6.7.7

Affected:
up to 6.7.7
Fixed in:
6.7.7

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database