Email Subscribers & Newsletters <= 5.9.16 - Authenticated (Administrator+) SQL Injection via 'workflow_ids' Parameter
Email Subscribers & Newsletters – Email Marketing, Post Notifications & Newsletter Plugin for WordPress
Minimum safe version
5.9.17
Update to 5.9.17 or later to address 48 fixable vulnerabilities
CVE-2025-12348
CVE-2025-66055
CVE-2025-12349
Email Subscribers & Newsletters <= 5.7.49 - Authenticated (Administrator+) Stored Cross-Site Scripting
CVE-2024-11924
CVE-2024-11636
CVE-2024-12568
CVE-2024-12566
CVE-2024-12567
CVE-2024-12311
CVE-2024-8254
CVE-2024-8771
CVE-2024-5703
CVE-2024-6172
CVE-2024-37252
CVE-2024-5756
CVE-2024-4845
CVE-2024-4295
CVE-2024-3626
CVE-2024-4010
CVE-2024-2876
CVE-2024-31352
CVE-2024-2656
CVE-2024-22300
CVE-2023-5414
CVE-2022-45810
Email Subscribers & Newsletters < 2.9.1 - Cross-Site Scripting
Email Subscribers & Newsletters < 2.9.1 - Multiple XSS & SQLi
Email Subscribers & Newsletters < 5.3.2 - Unauthenticated arbitrary option update
CVE-2022-3981
WordPress Email Subscribers Plugin <= 2.9 - Multiple Vulnerabilities
WordPress Email Subscribers & Newsletters plugin <=4.2.2 - Multiple security issues
WordPress Email Subscribers & Newsletters plugin <= 4.5.5 - Unauthenticated email forgery/spoofing vulnerability
CVE-2018-6015
CVE-2018-0602
Email Subscribers & Newsletters <= 4.1.7 - SQL Injection
WordPress Email Subscribers & Newsletters plugin <= 4.1.6 - Cross-Site Scripting (XSS) vulnerability
CVE-2019-19985
CVE-2019-19984
CVE-2019-19982
CVE-2019-19980
CVE-2019-19981
CVE-2019-20361
CVE-2020-5768
CVE-2020-5767
CVE-2020-5780
CVE-2022-0439