Cross Site Scripting Vulnerability in Newsletter Plugin by WordPress
CVE-2026-66596
7.1HIGH
What is CVE-2026-66596?
The Newsletter Plugin for WordPress versions 9.3.3 and earlier is susceptible to unauthenticated Cross Site Scripting (XSS) vulnerabilities. An attacker can exploit this weakness to inject arbitrary scripts into web pages viewed by users, posing a risk of cookie theft, session hijacking, and other malicious actions, affecting the security and privacy of site visitors.
Affected Version(s)
Newsletter <= 9.3.3