Stored Cross-Site Scripting in Newsletter Plugin for WordPress
CVE-2026-96566

7.2HIGH

What is CVE-2026-96566?

The Newsletter plugin for WordPress is susceptible to stored cross-site scripting vulnerabilities due to inadequate input sanitization and output escaping mechanisms. This allows unauthenticated attackers to inject malicious web scripts into the system, which can be executed when users access affected pages. The subscription endpoint lacks security measures, such as nonces and CAPTCHA, enabling attackers to bypass validations and smuggle payloads through specially crafted email addresses. Proper security practices must be implemented to safeguard against potential exploitation.

Affected Version(s)

Newsletter – Send awesome emails from WordPress 0 <= 9.4.0

References

CVSS V3.1

Score:
7.2
Severity:
HIGH
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

crow
.