PT-2026-95298 · WordPress · The Newsletter
CVSS v3.1
6.1
Medium
| Vector | AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
The Newsletter – Send awesome emails from WordPress versions prior to 9.3.9
Description
Reflected Cross-Site Scripting occurs due to insufficient input sanitization and output escaping. Unauthenticated attackers can inject arbitrary web scripts into pages by tricking a user into clicking a link. Exploitation requires the victim to be a logged-in administrator because the antibot check is bypassed for authenticated users, allowing the unsanitized payload to be processed by the
dienow() function via the nn parameter.Recommendations
Update to version 9.3.9 or later.
As a temporary mitigation, restrict access to the
nn parameter to prevent the execution of arbitrary scripts.Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
The Newsletter