CVE-2025-3582
- EPSS 0.17%
- Veröffentlicht 09.06.2025 06:00:13
- Zuletzt bearbeitet 12.06.2025 16:22:44
The Newsletter WordPress plugin before 8.85 does not sanitise and escape some of its Form settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disal...
CVE-2025-3581
- EPSS 0.17%
- Veröffentlicht 09.06.2025 06:00:01
- Zuletzt bearbeitet 12.06.2025 16:16:47
The Newsletter WordPress plugin before 8.8.5 does not validate and escape some of its Widget options before outputting them back in a page/post where the block is embed, which could allow high privilege users such as admin to perform Stored Cross-Si...
CVE-2025-3584
- EPSS 0.17%
- Veröffentlicht 03.06.2025 06:15:27
- Zuletzt bearbeitet 05.06.2025 14:10:30
The Newsletter WordPress plugin before 8.8.2 does not sanitise and escape some of its Subscription settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability...
CVE-2025-3583
- EPSS 0.17%
- Veröffentlicht 05.05.2025 06:15:31
- Zuletzt bearbeitet 07.05.2025 16:36:47
The Newsletter WordPress plugin before 8.7.1 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowe...
CVE-2024-5317
- EPSS 0.53%
- Veröffentlicht 05.06.2024 02:15:10
- Zuletzt bearbeitet 08.04.2026 18:22:02
The Newsletter plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'np1' parameter in all versions up to, and including, 8.3.4 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticate...
CVE-2023-4772
- EPSS 0.09%
- Veröffentlicht 07.09.2023 02:15:08
- Zuletzt bearbeitet 08.04.2026 18:18:16
The Newsletter plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'newsletter_form' shortcode in versions up to, and including, 7.8.9 due to insufficient input sanitization and output escaping on user supplied attributes. This ...
CVE-2023-27922
- EPSS 9.83%
- Veröffentlicht 23.05.2023 02:15:09
- Zuletzt bearbeitet 21.11.2024 07:53:42
Cross-site scripting vulnerability in Newsletter versions prior to 7.6.9 allows a remote unauthenticated attacker to inject an arbitrary script.
CVE-2022-1889
- EPSS 0.23%
- Veröffentlicht 20.06.2022 11:15:10
- Zuletzt bearbeitet 21.11.2024 06:41:41
The Newsletter WordPress plugin before 7.4.6 does not escape and sanitise the preheader_text setting, which could allow high privilege users to perform Stored Cross-Site Scripting attacks when the unfilteredhtml is disallowed
CVE-2022-1756
- EPSS 3.13%
- Veröffentlicht 13.06.2022 13:15:11
- Zuletzt bearbeitet 21.11.2024 06:41:24
The Newsletter WordPress plugin before 7.4.5 does not sanitize and escape the $_SERVER['REQUEST_URI'] before echoing it back in admin pages. Although this uses addslashes, and most modern browsers automatically URLEncode requests, this is still vulne...
CVE-2020-35933
- EPSS 0.12%
- Veröffentlicht 01.01.2021 02:15:13
- Zuletzt bearbeitet 21.11.2024 05:28:32
A Reflected Authenticated Cross-Site Scripting (XSS) vulnerability in the Newsletter plugin before 6.8.2 for WordPress allows remote attackers to trick a victim into submitting a tnpc_render AJAX request containing either JavaScript in an options par...