rootpwn

high · CVSS v3 7.2 · EPSS 0.00271

CVE-2026-96566

The WordPress Newsletter plugin (up to 9.4.0) contains a stored XSS flaw in the 'np1' custom field that allows unauthenticated users to inje

Overview

The WordPress Newsletter plugin (up to 9.4.0) contains a stored XSS flaw in the 'np1' custom field that allows unauthenticated users to inject scripts via the subscription endpoint. This flaw can execute arbitrary code in the context of any visitor who loads the affected page, potentially compromising site integrity and user data. The vulnerability is triggered without a nonce, capability check, or CAPTCHA, making it easy to exploit.

Description

The Newsletter – Send awesome emails from WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'np1' Custom Field Parameter in all versions up to, and including, 9.4.0 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. The subscription endpoint (na=sa) requires no nonce, no capability check, and no CAPTCHA, and the payload can be smuggled past email-address validation by embedding the {profile_1} placeholder in the local part of the submitted address, since WordPress's is_email() permits curly braces there.

Impact

Stored XSS can lead to theft of user credentials, session hijacking, or defacement of the site, affecting confidentiality, integrity, and potentially availability of the website. Site administrators and visitors are at risk, as any user who views the injected page will execute the malicious script. The attack does not require authentication, so all users are vulnerable.

Remediation

Update the Newsletter plugin to version 9.4.1 or later where the 'np1' field is properly sanitized and output escaped. If an update is not possible, disable the subscription endpoint or restrict it to authenticated users, add a nonce and capability check, and implement CAPTCHA to block automated submissions. Additionally, enforce a strong Content Security Policy (CSP) and ensure all user input is escaped before rendering.

Risk context

Severity is high with a CVSS v3 score of 7.2 and an EPSS of 0.00271, indicating a moderate likelihood of exploitation but significant impact if successful. Defenders should treat this as a priority patch to mitigate potential data compromise.

Affected products

  • WordPress Newsletter 9.4.0
  • WordPress Newsletter 9.3.x
  • WordPress Newsletter 9.2.x
  • WordPress Newsletter 9.1.x
  • WordPress Newsletter 9.0.x
  • WordPress Newsletter 8.x
  • WordPress Newsletter 7.x
  • WordPress Newsletter 6.x

Scores

Severity
high
CVSS v2
6.4
CVSS v3
7.2
CVSS v4
—
EPSS
0.00271

XSS WordPress Newsletter Stored XSS Input Sanitization High Severity

← All CVEs