Stored Cross-Site Scripting in Newsletters Lite Plugin for WordPress
CVE-2026-12938
6.4MEDIUM
What is CVE-2026-12938?
The Newsletters Lite plugin for WordPress suffers from a Stored Cross-Site Scripting vulnerability detected in the 'target' attribute of the [newsletters_post] shortcode. This flaw arises due to inadequate input sanitization and output escaping in key functions, allowing authenticated attackers with Contributor-level permissions and higher to inject arbitrary web scripts. These scripts will execute whenever a user accesses manipulated posts, posing significant security risks to the integrity of the site and its users.
Affected Version(s)
Newsletters 0 <= 4.15