Newsletter – Send awesome emails from
Newsletter – Send awesome emails from (newsletter) is a WordPress plugin with 21 published CVE records in this archive. The latest tracked vulnerability was published Oct 01, 2026; the highest published CVSS base score is 7.6.
newsletterCVE-2026-92537: Newsletter – Send awesome emails from WordPress: Tracking URLs expose permanent subscriber credentials
The Newsletter – Send awesome emails from WordPress plugin for WordPress is vulnerable to Insufficiently Protected Credentials in all versions up to, and including, 9.3.9 The plugin's public click-tracking REST route `/tnp/l/` is registered with `permission_callback => '__return_true'` and, upon receiving a valid keyed-MD5 signature, calls `set_user_cookie()`, which emits a `Set-Cookie: newsletter=
| Safe version |
|
||
|---|---|---|---|
| Oct 01, 2026 |
CVE-2026-92537
Newsletter – Send awesome emails from WordPress: Tracking URLs expose permanent subscriber credentials
The Newsletter – Send awesome emails from WordPress plugin for WordPress is vulnerable to Insufficiently Protected Credentials in all versions up to, and including, 9.3.9 The plugin's public click-tracking REST route `/tnp/l/` is registered with `permission_callback => '__return_true'` and, upon receiving a valid keyed-MD5 signature, calls `set_user_cookie()`, which emits a `Set-Cookie: newsletter=
|
9.4.0 |
CVE5.3
NVDPending
|
| Sep 18, 2026 |
CVE-2026-90981
Newsletter – Send awesome emails from WordPress: Reflected XSS reaches logged-in administrators
The Newsletter – Send awesome emails from WordPress plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'nn' parameter in all versions up to, and including, 9.3.8 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link. Successful exploitation requires the victim to be a logged-in administrator, as the antibot check auto-passes for authenticated users, routing the unsanitized payload through the administrator-visible output branch of dienow(). The attacker needs no login, but successful exploitation requires a logged-in administrator as the victim. The complete request route is not disclosed. Affected versions reported by the CNA: <= 9.3.8. Official changelog review confirms 9.3.9 as a fixed release for this issue.
|
9.3.9 |
CVE6.1
NVDPending
|
| Sep 17, 2026 |
CVE-2026-86824
Newsletter permits forged tracking links and subscriber-session access
Newsletter before 9.3.8 generates an email-tracking signing key with insufficient entropy and uses an unkeyed hash to sign tracking links. An unauthenticated attacker who first recovers that key offline can forge links to obtain a subscriber session token, then read and change the subscriber's stored personal data. The export does not disclose the recovery inputs, hash algorithm, link parameters or callback. The described session is a Newsletter subscriber session, not proof of WordPress administrator-login access.
|
9.3.8 |
CVE4.8
NVDPending
|
| Sep 16, 2026 |
CVE-2026-86823
Newsletter leaks subscriber tokens through an unrestricted redirect
Newsletter before 9.3.7: An unauthenticated attacker can control the destination of a redirect after a public subscription action. Redirecting a visitor to an external site can disclose a subscriber token that authorizes front-end actions for that subscriber record. The export does not identify the destination parameter, token transport or precise actions granted; it does not establish WordPress account takeover.
|
9.3.7 |
CVE5.3
NVDPending
|
| Aug 19, 2026 |
CVE-2026-66596
Newsletter: Cross-site scripting
Newsletter is affected by cross-site scripting. The vulnerable path is reachable without authentication. Injected script can execute in the affected site's origin when the vulnerable output is viewed. The published affected range is n/a through 9.3.3.
|
9.3.4 |
CVE7.1
NVDPending
|
| Jan 20, 2026 |
CVE-2026-1051
Newsletter – Send awesome emails from: Cross-site request forgery
Newsletter – Send awesome emails from is affected by cross-site request forgery. The vulnerable path is reachable without authentication. Exploitation relies on a signed-in privileged user submitting an attacker-controlled request.
|
See mitigation notes |
CVE4.3
NVDPending
|
| Dec 16, 2025 |
CVE-2025-67999
Newsletter: SQL injection
Newsletter is affected by SQL injection. Exposure depends on how the affected operation is made reachable by the site. A successful request can alter database queries and expose or modify WordPress data.
|
See mitigation notes |
CVE7.6
NVDPending
|
| Jun 09, 2025 |
CVE-2025-3582
Newsletter: Cross-site scripting
Newsletter is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVE4.8
NVDPending
|
| Jun 09, 2025 |
CVE-2025-3581
Newsletter: Cross-site scripting
Newsletter is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVE4.8
NVDPending
|
| Jun 03, 2025 |
CVE-2025-3584
Newsletter: Cross-site scripting
Newsletter is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVE4.8
NVDPending
|
| May 05, 2025 |
CVE-2025-3583
Newsletter: Cross-site scripting
Newsletter is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVE3.5
NVD4.8
|
| Jun 12, 2024 |
CVE-2024-5674
Newsletter - API v1 and v2 addon: A security weakness
Newsletter - API v1 and v2 addon is affected by a security weakness. The vulnerable path is reachable without authentication. The resulting impact depends on how the affected component exposes the vulnerable operation.
|
See mitigation notes |
CVE6.5
NVDPending
|
| Jun 05, 2024 |
CVE-2024-5317
Newsletter: Cross-site scripting
Newsletter is affected by cross-site scripting. The vulnerable path is reachable without authentication. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVE6.4
NVD6.1
|
| May 17, 2024 |
CVE-2024-30522
Newsletter: Privilege escalation or authentication bypass
Newsletter is affected by privilege escalation or authentication bypass. Exposure depends on how the affected operation is made reachable by the site. A successful request can grant permissions or access that the caller should not possess.
|
See mitigation notes |
CVE5.3
NVDPending
|
| Apr 15, 2024 |
CVE-2024-31434
Newsletter: Cross-site request forgery
Newsletter is affected by cross-site request forgery. Exposure depends on how the affected operation is made reachable by the site. Exploitation relies on a signed-in privileged user submitting an attacker-controlled request.
|
See mitigation notes |
CVE5.4
NVDPending
|
| Sep 07, 2023 |
CVE-2023-4772
Newsletter: Cross-site scripting
Newsletter is affected by cross-site scripting. Exploitation requires an authenticated contributor account. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVE6.4
NVD5.4
|
| May 23, 2023 |
CVE-2023-27922
Newsletter: Cross-site scripting
Newsletter is affected by cross-site scripting. The vulnerable path is reachable without authentication. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVEPending
NVD6.1
|
| Jun 20, 2022 |
CVE-2022-1889
Newsletter: Cross-site scripting
Newsletter is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVEPending
NVD4.8
|
| Jun 13, 2022 |
CVE-2022-1756
Newsletter: Cross-site scripting
Newsletter is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVEPending
NVD6.1
|
| Jan 01, 2021 |
CVE-2020-35933
Newsletter: Cross-site scripting
Newsletter is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVE6.5
NVD6.5
|
| Jan 01, 2021 |
CVE-2020-35932
Newsletter: Code execution
Newsletter is affected by code execution. Exposure depends on how the affected operation is made reachable by the site. Successful exploitation can run attacker-controlled code in the WordPress hosting account.
|
See mitigation notes |
CVE7.5
NVD8.8
|