Reflected Cross-Site Scripting in Newsletter Plugin for WordPress
CVE-2026-90981
6.1MEDIUM
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 18 September 2026
What is CVE-2026-90981?
The Newsletter plugin for WordPress is vulnerable to reflected cross-site scripting (XSS) through the 'nn' parameter in all releases up to and including version 9.3.8. This vulnerability arises from inadequate input sanitization and output escaping, allowing an attacker to inject arbitrary web scripts. Such exploitation necessitates that the targeted user is a logged-in administrator, as the antibot measures bypass input validation for authenticated users. If an attacker successfully convinces the administrator to perform a specific action, they can trigger the execution of malicious scripts, compromising the security of the site.
Affected Version(s)
Newsletter β Send awesome emails from WordPress 0 <= 9.3.8