← WordPress Vulnerabilities
WordPress security by component

Newsletter – Send awesome emails from

Newsletter – Send awesome emails from is a WordPress component with 16 published CVE records in this archive. The latest tracked vulnerability was published Jan 20, 2026; the highest CVE/CNA score is 7.6.

Plugin slug: newsletter

CVE-2026-1051: Newsletter – Send awesome emails from: Cross-site request forgery

Newsletter – Send awesome emails from is affected by cross-site request forgery. The vulnerable path is reachable without authentication. Exploitation relies on a signed-in privileged user submitting an attacker-controlled request.

PublishedJan 20, 2026
Safe version guidanceSee mitigation notes
Safe version
Jan 20, 2026 CVE-2026-1051
Newsletter – Send awesome emails from: Cross-site request forgery
Newsletter – Send awesome emails from is affected by cross-site request forgery. The vulnerable path is reachable without authentication. Exploitation relies on a signed-in privileged user submitting an attacker-controlled request.
See mitigation notes
CVE4.3
NVDPending
Dec 16, 2025 CVE-2025-67999
Newsletter: SQL injection
Newsletter is affected by SQL injection. Exposure depends on how the affected operation is made reachable by the site. A successful request can alter database queries and expose or modify WordPress data.
See mitigation notes
CVE7.6
NVDPending
Jun 09, 2025 CVE-2025-3582
Newsletter: Cross-site scripting
Newsletter is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE4.8
NVDPending
Jun 09, 2025 CVE-2025-3581
Newsletter: Cross-site scripting
Newsletter is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE4.8
NVDPending
Jun 03, 2025 CVE-2025-3584
Newsletter: Cross-site scripting
Newsletter is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE4.8
NVDPending
May 05, 2025 CVE-2025-3583
Newsletter: Cross-site scripting
Newsletter is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE3.5
NVD4.8
Jun 12, 2024 CVE-2024-5674
Newsletter - API v1 and v2 addon: A security weakness
Newsletter - API v1 and v2 addon is affected by a security weakness. The vulnerable path is reachable without authentication. The resulting impact depends on how the affected component exposes the vulnerable operation.
See mitigation notes
CVE6.5
NVDPending
Jun 05, 2024 CVE-2024-5317
Newsletter: Cross-site scripting
Newsletter is affected by cross-site scripting. The vulnerable path is reachable without authentication. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE6.4
NVD6.1
May 17, 2024 CVE-2024-30522
Newsletter: Privilege escalation or authentication bypass
Newsletter is affected by privilege escalation or authentication bypass. Exposure depends on how the affected operation is made reachable by the site. A successful request can grant permissions or access that the caller should not possess.
See mitigation notes
CVE5.3
NVDPending
Apr 15, 2024 CVE-2024-31434
Newsletter: Cross-site request forgery
Newsletter is affected by cross-site request forgery. Exposure depends on how the affected operation is made reachable by the site. Exploitation relies on a signed-in privileged user submitting an attacker-controlled request.
See mitigation notes
CVE5.4
NVDPending
Sep 07, 2023 CVE-2023-4772
Newsletter: Cross-site scripting
Newsletter is affected by cross-site scripting. Exploitation requires an authenticated WordPress account. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE6.4
NVD5.4
May 23, 2023 CVE-2023-27922
Newsletter: Cross-site scripting
Newsletter is affected by cross-site scripting. The vulnerable path is reachable without authentication. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE6.1
NVD6.1
Jun 20, 2022 CVE-2022-1889
Newsletter: Cross-site scripting
Newsletter is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE4.8
NVD4.8
Jun 13, 2022 CVE-2022-1756
Newsletter: Cross-site scripting
Newsletter is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE6.1
NVD6.1
Jan 01, 2021 CVE-2020-35933
Newsletter: Cross-site scripting
Newsletter is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE6.5
NVD6.5
Jan 01, 2021 CVE-2020-35932
Newsletter: Code execution
Newsletter is affected by code execution. Exposure depends on how the affected operation is made reachable by the site. Successful exploitation can run attacker-controlled code in the WordPress hosting account.
See mitigation notes
CVE7.5
NVD8.8