Newsletter <= 8.8.4 - Authenticated (Administrator+) Stored Cross-Site Scripting
Newsletter – Send awesome emails from WordPress
Minimum safe version
9.1.1
Update to 9.1.1 or later to address 33 fixable vulnerabilities
Newsletter <= 8.8.4 - Authenticated (Administrator+) Stored Cross-Site Scripting
Newsletter – Send awesome emails from WordPress <= 9.1.0 - Cross-Site Request Forgery to Newsletter Unsubscription
CVE-2025-67999
Newsletter <= 8.8.1 - Authenticated (Admin+) Stored Cross-Site Scripting
WordPress Newsletter Plugin < 8.7.1 is vulnerable to Cross Site Scripting (XSS)
CVE-2024-5317
CVE-2024-31434
CVE-2024-30522
Newsletter <= 8.0.6 - Cross-Site Request Forgery
CVE-2023-4772
Newsletter < 3.0.9 - SQL Injection
Newsletter < 3.2.7 - Cross-Site Scripting (XSS)
Newsletter 3.7.0 - Open Redirect
Newsletter < 6.5.4 - CSV Injection
Newsletter < 6.7.7 - Authenticated Stored Cross-Site Scripting
CVE-2023-27922
WordPress Newsletter Plugin <= 7.6.8 is vulnerable to Cross Site Scripting (XSS)
Newsletter <= 7.6.8 - Reflected Cross-Site Scripting
Newsletter <= 3.2.6 - Reflected Cross-Site Scripting
Newsletter <= 3.8.2 - Open Redirect
Newsletter <= 6.5.3 - CSV Injection
Newsletter <= 6.7.6 - Stored Cross-Site Scripting
WordPress Newsletter Plugin <= 3.7.0 - Open Redirection
CVE-2022-1889
WordPress Newsletter plugin <= 7.4.4 - Reflected Cross-Site Scripting (XSS) vulnerability
WordPress Newsletter Plugin <= 3.2.6 - Cross Site Scripting
WordPress Newsletter Plugin <= 3.0.8 - SQL Injection
WordPress Plugin "Newsletter" vulnerable to cross-site scripting
WordPress Newsletter plugin <= 6.7.6 - Authenticated Stored Cross-Site Scripting (XSS) vulnerability
WordPress Newsletter plugin <= 6.5.3 - CSV Injection vulnerability
CVE-2020-35933
CVE-2020-35932