Stored Cross-Site Scripting in Newsletter Plugin for WordPress
CVE-2026-96566
7.2HIGH
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 2 October 2026
What is CVE-2026-96566?
The Newsletter plugin for WordPress is susceptible to stored cross-site scripting vulnerabilities due to inadequate input sanitization and output escaping mechanisms. This allows unauthenticated attackers to inject malicious web scripts into the system, which can be executed when users access affected pages. The subscription endpoint lacks security measures, such as nonces and CAPTCHA, enabling attackers to bypass validations and smuggle payloads through specially crafted email addresses. Proper security practices must be implemented to safeguard against potential exploitation.
Affected Version(s)
Newsletter β Send awesome emails from WordPress 0 <= 9.4.0