high · CVSS v3 7.2 · EPSS 0.00271
CVE-2026-96566
The WordPress Newsletter plugin (up to 9.4.0) contains a stored XSS flaw in the 'np1' custom field that allows unauthenticated users to inje
Overview
The WordPress Newsletter plugin (up to 9.4.0) contains a stored XSS flaw in the 'np1' custom field that allows unauthenticated users to inject scripts via the subscription endpoint. This flaw can execute arbitrary code in the context of any visitor who loads the affected page, potentially compromising site integrity and user data. The vulnerability is triggered without a nonce, capability check, or CAPTCHA, making it easy to exploit.
Description
The Newsletter – Send awesome emails from WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'np1' Custom Field Parameter in all versions up to, and including, 9.4.0 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. The subscription endpoint (na=sa) requires no nonce, no capability check, and no CAPTCHA, and the payload can be smuggled past email-address validation by embedding the {profile_1} placeholder in the local part of the submitted address, since WordPress's is_email() permits curly braces there.
Impact
Stored XSS can lead to theft of user credentials, session hijacking, or defacement of the site, affecting confidentiality, integrity, and potentially availability of the website. Site administrators and visitors are at risk, as any user who views the injected page will execute the malicious script. The attack does not require authentication, so all users are vulnerable.
Remediation
Update the Newsletter plugin to version 9.4.1 or later where the 'np1' field is properly sanitized and output escaped. If an update is not possible, disable the subscription endpoint or restrict it to authenticated users, add a nonce and capability check, and implement CAPTCHA to block automated submissions. Additionally, enforce a strong Content Security Policy (CSP) and ensure all user input is escaped before rendering.
Risk context
Severity is high with a CVSS v3 score of 7.2 and an EPSS of 0.00271, indicating a moderate likelihood of exploitation but significant impact if successful. Defenders should treat this as a priority patch to mitigate potential data compromise.
Affected products
- WordPress Newsletter 9.4.0
- WordPress Newsletter 9.3.x
- WordPress Newsletter 9.2.x
- WordPress Newsletter 9.1.x
- WordPress Newsletter 9.0.x
- WordPress Newsletter 8.x
- WordPress Newsletter 7.x
- WordPress Newsletter 6.x
Scores
- Severity
- high
- CVSS v2
- 6.4
- CVSS v3
- 7.2
- CVSS v4
- —
- EPSS
- 0.00271