Executive brief
Email Subscribers & Newsletters is a WordPress plugin used to build and manage email marketing campaigns. An unauthenticated cross-site scripting (XSS) vulnerability in versions up to 5.9.33 allows attackers to inject malicious scripts that can steal visitor data, hijack user accounts, or deface website content. Exploitation requires user interaction (e.g., clicking a malicious link), but poses a significant risk to website visitors and administrators.
Technical details
This is an unauthenticated cross-site scripting (XSS) vulnerability in the Email Subscribers & Newsletters WordPress plugin affecting versions 5.9.33 and earlier. The vulnerability allows attackers to inject malicious JavaScript code that executes in the context of affected users' browsers. No authentication is required to exploit this issue, though successful exploitation requires user interaction such as clicking a link or visiting a crafted page. Attackers can leverage this to steal sensitive data, hijack accounts, or perform actions on behalf of compromised users. The vulnerability has been patched in version 5.9.34 and later; users should update immediately.
Affected products
- WordPress Email Subscribers & Newsletters 5.9.33 and earlier
Timeline
- 2026-08-31: disclosed: Published on NVD
- 2026-08-27: other: Reported to Patchstack; patched in version 5.9.34
- 2026-08-05: other: Initially reported by Jiemook