Executive brief
The Newsletter is a WordPress plugin used to send email campaigns and newsletters to site visitors and customers. An unauthenticated attacker can inject malicious JavaScript code through a specially crafted link that, when clicked by a logged-in site administrator, will execute in the administrator's browser. This could allow the attacker to steal administrator credentials, modify site content, or perform other administrative actions on behalf of the compromised admin.
Technical details
The vulnerability is a reflected cross-site scripting (XSS) flaw in the 'nn' parameter of The Newsletter plugin, caused by insufficient input sanitization and output escaping. The dienow() function routes traffic through an antibot check that auto-passes for authenticated users, allowing unsanitized payloads to reach administrator-visible output without proper sanitization. An unauthenticated attacker can craft a malicious URL and social-engineer a logged-in administrator into clicking it, causing arbitrary JavaScript to execute in the admin's browser session. The vulnerability affects all versions up to and including 9.3.8. A patch is expected to be available in a newer version.
Affected products
- The Newsletter The Newsletter up to and including 9.3.8
Timeline
- 2026-09-18: disclosed