The Newsletter Plugin is a WordPress plugin with a narrow product footprint but notable presence in the WordPress ecosystem, focusing on email newsletter and subscription management functionality. Its vulnerability disclosure pattern centers on cross-site scripting flaws arising from improper input neutralization in web page generation, a characteristic weakness in user-facing content-handling code. Vulnerabilities affecting this plugin have an elevated tendency toward public exploit availability; defenders should prioritize patches for this component when deployed in WordPress installations that accept user content or permit plugin-to-admin interaction. Current severity, exploitation status, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Thenewsletterplugin over time
Signals from CVEs in this vendor scope (10 CVEs).
10 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2022-1756MEDIUM The Newsletter WordPress plugin before 7.4.5 does not sanitize and escape the $_SERVER['REQUEST_URI'] before echoing it back in admin pages. Although this uses addslashes, and most | Jun 13, 2022 | 6.1 | 32 | NO | YES |
CVE-2023-27922MEDIUM Cross-site scripting vulnerability in Newsletter versions prior to 7.6.9 allows a remote unauthenticated attacker to inject an arbitrary script. | May 23, 2023 | 6.1 | 29 | NO | YES |
CVE-2020-35933MEDIUM A Reflected Authenticated Cross-Site Scripting (XSS) vulnerability in the Newsletter plugin before 6.8.2 for WordPress allows remote attackers to trick a victim into submitting a t | Jan 1, 2021 | 6.5 | 22 | NO | NO |
CVE-2024-5317MEDIUM The Newsletter plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'np1' parameter in all versions up to, and including, 8.3.4 due to insufficient input sanit | Jun 5, 2024 | 6.1 | 18 | NO | NO |
CVE-2025-3584MEDIUM The Newsletter WordPress plugin before 8.8.2 does not sanitise and escape some of its Subscription settings, which could allow high privilege users such as admin to perform Stored | Jun 3, 2025 | 4.8 | 17 | NO | NO |
CVE-2025-3582MEDIUM The Newsletter WordPress plugin before 8.85 does not sanitise and escape some of its Form settings, which could allow high privilege users such as admin to perform Stored Cross-Si | Jun 9, 2025 | 4.8 | 16 | NO | NO |
CVE-2025-3583MEDIUM The Newsletter WordPress plugin before 8.7.1 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site S | May 5, 2025 | 4.8 | 16 | NO | NO |
CVE-2025-3581MEDIUM The Newsletter WordPress plugin before 8.8.5 does not validate and escape some of its Widget options before outputting them back in a page/post where the block is embed, which cou | Jun 9, 2025 | 4.8 | 15 | NO | NO |
CVE-2023-4772MEDIUM The Newsletter plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'newsletter_form' shortcode in versions up to, and including, 7.8.9 due to insufficient inp | Sep 7, 2023 | 5.4 | 15 | NO | NO |
CVE-2022-1889MEDIUM The Newsletter WordPress plugin before 7.4.6 does not escape and sanitise the preheader_text setting, which could allow high privilege users to perform Stored Cross-Site Scripting | Jun 20, 2022 | 4.8 | 15 | NO | NO |
Signals from CVEs in this vendor scope (10 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Thenewsletterplugin.
Media articles that mention a CVE ID that affects a product developed by Thenewsletterplugin — matched by CVE ID, not by vendor name.