Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Thenewsletterplugin

First CVE: Jan 1, 2021Active for: 6 yearsTotal CVEs: 10
20.3
VTI Score
Low

The Newsletter Plugin is a WordPress plugin with a narrow product footprint but notable presence in the WordPress ecosystem, focusing on email newsletter and subscription management functionality. Its vulnerability disclosure pattern centers on cross-site scripting flaws arising from improper input neutralization in web page generation, a characteristic weakness in user-facing content-handling code. Vulnerabilities affecting this plugin have an elevated tendency toward public exploit availability; defenders should prioritize patches for this component when deployed in WordPress installations that accept user content or permit plugin-to-admin interaction. Current severity, exploitation status, and exposure counts are shown alongside this summary.

FAUCET AI Generated
10
Total CVEs
More Total CVEs than 92% of tracked vendors
2.0
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 80% of tracked vendors
5.4
Avg CVSS Score
Higher Avg CVSS Score than 22% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Thenewsletterplugin over time

Volume of CVEsAvg CVSS Base Score
First CVE
Jan 1, 2021
5 years ago
Most Recent CVE
Jun 9, 2025
413 days ago

Products(1 total)

Top CVEs

Signals from CVEs in this vendor scope (10 CVEs).

10 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2022-1756MEDIUM
The Newsletter WordPress plugin before 7.4.5 does not sanitize and escape the $_SERVER['REQUEST_URI'] before echoing it back in admin pages. Although this uses addslashes, and most
Jun 13, 20226.132NOYES
CVE-2023-27922MEDIUM
Cross-site scripting vulnerability in Newsletter versions prior to 7.6.9 allows a remote unauthenticated attacker to inject an arbitrary script.
May 23, 20236.129NOYES
CVE-2020-35933MEDIUM
A Reflected Authenticated Cross-Site Scripting (XSS) vulnerability in the Newsletter plugin before 6.8.2 for WordPress allows remote attackers to trick a victim into submitting a t
Jan 1, 20216.522NONO
CVE-2024-5317MEDIUM
The Newsletter plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'np1' parameter in all versions up to, and including, 8.3.4 due to insufficient input sanit
Jun 5, 20246.118NONO
CVE-2025-3584MEDIUM
The Newsletter WordPress plugin before 8.8.2 does not sanitise and escape some of its Subscription settings, which could allow high privilege users such as admin to perform Stored
Jun 3, 20254.817NONO
CVE-2025-3582MEDIUM
The Newsletter WordPress plugin before 8.85 does not sanitise and escape some of its Form settings, which could allow high privilege users such as admin to perform Stored Cross-Si
Jun 9, 20254.816NONO
CVE-2025-3583MEDIUM
The Newsletter WordPress plugin before 8.7.1 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site S
May 5, 20254.816NONO
CVE-2025-3581MEDIUM
The Newsletter WordPress plugin before 8.8.5 does not validate and escape some of its Widget options before outputting them back in a page/post where the block is embed, which cou
Jun 9, 20254.815NONO
CVE-2023-4772MEDIUM
The Newsletter plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'newsletter_form' shortcode in versions up to, and including, 7.8.9 due to insufficient inp
Sep 7, 20235.415NONO
CVE-2022-1889MEDIUM
The Newsletter WordPress plugin before 7.4.6 does not escape and sanitise the preheader_text setting, which could allow high privilege users to perform Stored Cross-Site Scripting
Jun 20, 20224.815NONO
View all 10 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products10 CVEs
100%
Severity distribution among all CVEs352,785 CVEs
45%
40%
11%
Medium
Attack Vector
Local0 (0.0%)
Network10 (100.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low10 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None0 (0.0%)
Unknown0 (0.0%)
Required10 (100.0%)
Privileges Required
Low2 (20.0%)
High5 (50.0%)
None3 (30.0%)
Unknown0 (0.0%)

Exploit Exposure

Signals from CVEs in this vendor scope (10 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
2 CVEs
20.0% of CVEs· 97th percentile
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Thenewsletterplugin.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Thenewsletterplugin — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Thenewsletterplugin's Products

View all 4 CNAs →

Top CWEs