← WordPress Vulnerabilities
WordPress security by component

Newsletter – Send awesome emails from

Newsletter – Send awesome emails from (newsletter) is a WordPress plugin with 21 published CVE records in this archive. The latest tracked vulnerability was published Oct 01, 2026; the highest published CVSS base score is 7.6.

Plugin slug: newsletter

CVE-2026-92537: Newsletter – Send awesome emails from WordPress: Tracking URLs expose permanent subscriber credentials

The Newsletter – Send awesome emails from WordPress plugin for WordPress is vulnerable to Insufficiently Protected Credentials in all versions up to, and including, 9.3.9 The plugin's public click-tracking REST route `/tnp/l/` is registered with `permission_callback => '__return_true'` and, upon receiving a valid keyed-MD5 signature, calls `set_user_cookie()`, which emits a `Set-Cookie: newsletter=-` response header to the requester because the subscriber object loaded via `get_user()` lacks the `_trusted` property, causing `get_user_key()` to return the raw token column value instead of its MD5-masked variant. This makes it possible for unauthenticated attackers who obtain any signed click-tracking URL for a target subscriber to receive that subscriber's permanent raw authentication cookie, which they can then use to export the subscriber's full PII record via the JSON profile-export endpoint (`?na=px`), rewrite the subscriber's stored profile (`?na=ps`), and silently unsubscribe the subscriber via the RFC-8058 one-click endpoint (`?na=ocu`), none of which require a nonce, password, or email challenge. Signed tracking URLs are embedded in every external link of every newsletter delivered to a subscriber, carry no timestamp, and never expire until the site's relink key rotates, meaning that any party who observes such a URL — through a forwarded email, a shared inbox, a mail-gateway log, or Referer headers on the redirect target, which has no Referrer-Policy set — can replay it indefinitely to obtain the victim's credential. The official changelog confirms a matching fix in 9.4.0.

PublishedOct 01, 2026
Known safe version9.4.0
Published vulnerabilities for newsletter
Safe version
Oct 01, 2026 CVE-2026-92537
Newsletter – Send awesome emails from WordPress: Tracking URLs expose permanent subscriber credentials
The Newsletter – Send awesome emails from WordPress plugin for WordPress is vulnerable to Insufficiently Protected Credentials in all versions up to, and including, 9.3.9 The plugin's public click-tracking REST route `/tnp/l/` is registered with `permission_callback => '__return_true'` and, upon receiving a valid keyed-MD5 signature, calls `set_user_cookie()`, which emits a `Set-Cookie: newsletter=-` response header to the requester because the subscriber object loaded via `get_user()` lacks the `_trusted` property, causing `get_user_key()` to return the raw token column value instead of its MD5-masked variant. This makes it possible for unauthenticated attackers who obtain any signed click-tracking URL for a target subscriber to receive that subscriber's permanent raw authentication cookie, which they can then use to export the subscriber's full PII record via the JSON profile-export endpoint (`?na=px`), rewrite the subscriber's stored profile (`?na=ps`), and silently unsubscribe the subscriber via the RFC-8058 one-click endpoint (`?na=ocu`), none of which require a nonce, password, or email challenge. Signed tracking URLs are embedded in every external link of every newsletter delivered to a subscriber, carry no timestamp, and never expire until the site's relink key rotates, meaning that any party who observes such a URL — through a forwarded email, a shared inbox, a mail-gateway log, or Referer headers on the redirect target, which has no Referrer-Policy set — can replay it indefinitely to obtain the victim's credential. The official changelog confirms a matching fix in 9.4.0.
9.4.0
CVE5.3
NVDPending
Sep 18, 2026 CVE-2026-90981
Newsletter – Send awesome emails from WordPress: Reflected XSS reaches logged-in administrators
The Newsletter – Send awesome emails from WordPress plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'nn' parameter in all versions up to, and including, 9.3.8 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link. Successful exploitation requires the victim to be a logged-in administrator, as the antibot check auto-passes for authenticated users, routing the unsanitized payload through the administrator-visible output branch of dienow(). The attacker needs no login, but successful exploitation requires a logged-in administrator as the victim. The complete request route is not disclosed. Affected versions reported by the CNA: <= 9.3.8. Official changelog review confirms 9.3.9 as a fixed release for this issue.
9.3.9
CVE6.1
NVDPending
Sep 17, 2026 CVE-2026-86824
Newsletter permits forged tracking links and subscriber-session access
Newsletter before 9.3.8 generates an email-tracking signing key with insufficient entropy and uses an unkeyed hash to sign tracking links. An unauthenticated attacker who first recovers that key offline can forge links to obtain a subscriber session token, then read and change the subscriber's stored personal data. The export does not disclose the recovery inputs, hash algorithm, link parameters or callback. The described session is a Newsletter subscriber session, not proof of WordPress administrator-login access.
9.3.8
CVE4.8
NVDPending
Sep 16, 2026 CVE-2026-86823
Newsletter leaks subscriber tokens through an unrestricted redirect
Newsletter before 9.3.7: An unauthenticated attacker can control the destination of a redirect after a public subscription action. Redirecting a visitor to an external site can disclose a subscriber token that authorizes front-end actions for that subscriber record. The export does not identify the destination parameter, token transport or precise actions granted; it does not establish WordPress account takeover.
9.3.7
CVE5.3
NVDPending
Aug 19, 2026 CVE-2026-66596
Newsletter: Cross-site scripting
Newsletter is affected by cross-site scripting. The vulnerable path is reachable without authentication. Injected script can execute in the affected site's origin when the vulnerable output is viewed. The published affected range is n/a through 9.3.3.
9.3.4
CVE7.1
NVDPending
Jan 20, 2026 CVE-2026-1051
Newsletter – Send awesome emails from: Cross-site request forgery
Newsletter – Send awesome emails from is affected by cross-site request forgery. The vulnerable path is reachable without authentication. Exploitation relies on a signed-in privileged user submitting an attacker-controlled request.
See mitigation notes
CVE4.3
NVDPending
Dec 16, 2025 CVE-2025-67999
Newsletter: SQL injection
Newsletter is affected by SQL injection. Exposure depends on how the affected operation is made reachable by the site. A successful request can alter database queries and expose or modify WordPress data.
See mitigation notes
CVE7.6
NVDPending
Jun 09, 2025 CVE-2025-3582
Newsletter: Cross-site scripting
Newsletter is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE4.8
NVDPending
Jun 09, 2025 CVE-2025-3581
Newsletter: Cross-site scripting
Newsletter is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE4.8
NVDPending
Jun 03, 2025 CVE-2025-3584
Newsletter: Cross-site scripting
Newsletter is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE4.8
NVDPending
May 05, 2025 CVE-2025-3583
Newsletter: Cross-site scripting
Newsletter is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE3.5
NVD4.8
Jun 12, 2024 CVE-2024-5674
Newsletter - API v1 and v2 addon: A security weakness
Newsletter - API v1 and v2 addon is affected by a security weakness. The vulnerable path is reachable without authentication. The resulting impact depends on how the affected component exposes the vulnerable operation.
See mitigation notes
CVE6.5
NVDPending
Jun 05, 2024 CVE-2024-5317
Newsletter: Cross-site scripting
Newsletter is affected by cross-site scripting. The vulnerable path is reachable without authentication. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE6.4
NVD6.1
May 17, 2024 CVE-2024-30522
Newsletter: Privilege escalation or authentication bypass
Newsletter is affected by privilege escalation or authentication bypass. Exposure depends on how the affected operation is made reachable by the site. A successful request can grant permissions or access that the caller should not possess.
See mitigation notes
CVE5.3
NVDPending
Apr 15, 2024 CVE-2024-31434
Newsletter: Cross-site request forgery
Newsletter is affected by cross-site request forgery. Exposure depends on how the affected operation is made reachable by the site. Exploitation relies on a signed-in privileged user submitting an attacker-controlled request.
See mitigation notes
CVE5.4
NVDPending
Sep 07, 2023 CVE-2023-4772
Newsletter: Cross-site scripting
Newsletter is affected by cross-site scripting. Exploitation requires an authenticated contributor account. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE6.4
NVD5.4
May 23, 2023 CVE-2023-27922
Newsletter: Cross-site scripting
Newsletter is affected by cross-site scripting. The vulnerable path is reachable without authentication. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVEPending
NVD6.1
Jun 20, 2022 CVE-2022-1889
Newsletter: Cross-site scripting
Newsletter is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVEPending
NVD4.8
Jun 13, 2022 CVE-2022-1756
Newsletter: Cross-site scripting
Newsletter is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVEPending
NVD6.1
Jan 01, 2021 CVE-2020-35933
Newsletter: Cross-site scripting
Newsletter is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE6.5
NVD6.5
Jan 01, 2021 CVE-2020-35932
Newsletter: Code execution
Newsletter is affected by code execution. Exposure depends on how the affected operation is made reachable by the site. Successful exploitation can run attacker-controlled code in the WordPress hosting account.
See mitigation notes
CVE7.5
NVD8.8