VYPR
Vendor

Thenewsletterplugin

Products
1
CVEs
13
Across products
13
Status
Private

Products

1

Recent CVEs

13
  • CVE-2024-5674MedJun 12, 2024
    risk 0.42cvss 6.5epss 0.00

    The Newsletter - API v1 and v2 addon plugin for WordPress is vulnerable to unauthorized subscribers management due to PHP type juggling issue on the check_api_key function in all versions up to, and including, 2.4.5. This makes it possible for unauthenticated attackers to list,…

  • CVE-2020-35933MedJan 1, 2021
    risk 0.42cvss 6.5epss 0.01

    A Reflected Authenticated Cross-Site Scripting (XSS) vulnerability in the Newsletter plugin before 6.8.2 for WordPress allows remote attackers to trick a victim into submitting a tnpc_render AJAX request containing either JavaScript in an options parameter, or a base64-encoded…

  • CVE-2023-27922MedMay 23, 2023
    risk 0.40cvss 6.1epss 0.01

    Cross-site scripting vulnerability in Newsletter versions prior to 7.6.9 allows a remote unauthenticated attacker to inject an arbitrary script.

  • CVE-2022-1756MedJun 13, 2022
    risk 0.40cvss 6.1epss 0.02

    The Newsletter WordPress plugin before 7.4.5 does not sanitize and escape the $_SERVER['REQUEST_URI'] before echoing it back in admin pages. Although this uses addslashes, and most modern browsers automatically URLEncode requests, this is still vulnerable to Reflected XSS in…

  • CVE-2024-5317MedJun 5, 2024
    risk 0.35cvss 6.4epss 0.00

    The Newsletter plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'np1' parameter in all versions up to, and including, 8.3.4 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject…

  • CVE-2023-4772MedSep 7, 2023
    risk 0.35cvss 6.4epss 0.00

    The Newsletter plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'newsletter_form' shortcode in versions up to, and including, 7.8.9 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for…

  • CVE-2025-3582MedJun 9, 2025
    risk 0.31cvss 4.8epss 0.00

    The Newsletter WordPress plugin before 8.85 does not sanitise and escape some of its Form settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in…

  • CVE-2025-3581MedJun 9, 2025
    risk 0.31cvss 4.8epss 0.00

    The Newsletter WordPress plugin before 8.8.5 does not validate and escape some of its Widget options before outputting them back in a page/post where the block is embed, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even…

  • CVE-2025-3584MedJun 3, 2025
    risk 0.31cvss 4.8epss 0.00

    The Newsletter WordPress plugin before 8.8.2 does not sanitise and escape some of its Subscription settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example…

  • CVE-2025-3583MedMay 5, 2025
    risk 0.31cvss 4.8epss 0.00

    The Newsletter WordPress plugin before 8.7.1 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite…

  • CVE-2022-1889MedJun 20, 2022
    risk 0.31cvss 4.8epss 0.01

    The Newsletter WordPress plugin before 7.4.6 does not escape and sanitise the preheader_text setting, which could allow high privilege users to perform Stored Cross-Site Scripting attacks when the unfilteredhtml is disallowed

  • CVE-2006-1692Apr 11, 2006
    risk 0.00cvss epss 0.01

    Multiple SQL injection vulnerabilities in MWNewsletter 1.0.0b allow remote attackers to execute arbitrary SQL commands via the (1) user_email parameter to (a) unsubscribe.php or (b) subscribe.php; or the (2) user_name parameter to subscribe.php. NOTE: the provenance of this…

  • CVE-2006-1690Apr 11, 2006
    risk 0.00cvss epss 0.02

    Cross-site scripting (XSS) vulnerability in subscribe.php in MWNewsletter 1.0.0b allows remote attackers to inject arbitrary web script or HTML via the user_name parameter.

VYPR — Vulnerability Intelligence