Extension WordPress
Vulnérabilités Newsletter – Send awesome emails from WordPress
Cette page rassemble les failles publiées pour Newsletter – Send awesome emails from WordPress, leurs plages de versions affectées et les correctifs signalés dans la base locale.
Historique de sécurité
CVE et vulnérabilités de Newsletter – Send awesome emails from WordPress
20 fiches
Newsletter – Send awesome emails from WordPress <= 9.1.0 – Cross-Site Request Forgery to Newsletter Unsubscription
The Newsletter – Send awesome emails from WordPress plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 9.1.0. This is due to missing or incorrect nonce validation on the hook_newsletter_action() function.…
*-9.1.0
9.1.1
19/01/2026
Newsletter <= 9.0.9 – Authenticated (Administrator+) SQL Injection
The Newsletter plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 9.0.9 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes…
*-9.0.9
9.1.0
15/12/2025
Newsletter <= 8.8.4 – Authenticated (Administrator+) Stored Cross-Site Scripting
The Newsletter – Send awesome emails from WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 8.8.4 due to insufficient input sanitization and output escaping. This makes…
*-8.8.4
8.8.5
19/05/2025
Newsletter <= 8.8.4 – Authenticated (Administrator+) Stored Cross-Site Scripting
The Newsletter – Send awesome emails from WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 8.8.4 due to insufficient input sanitization and output escaping. This makes…
*-8.8.4
8.8.5
19/05/2025
Newsletter <= 8.8.1 – Authenticated (Admin+) Stored Cross-Site Scripting
The Newsletter – Send awesome emails from WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 8.8.1 due to insufficient input sanitization and output escaping. This makes…
*-8.8.1
8.8.2
13/05/2025
Newsletter <= 8.7.0 – Authenticated (Admin+) Stored Cross-Site Scripting
The Newsletter plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the preheader_text value in versions up to, and including, 8.7.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers with…
*-8.7.0
8.7.1
14/04/2025
Newsletter <= 8.3.4 – Unauthenticated Stored Cross-Site Scripting via np1
The Newsletter plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'np1' parameter in all versions up to, and including, 8.3.4 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers…
*-8.3.4
8.3.5
04/06/2024
Newsletter <= 8.0.6 – Cross-Site Request Forgery
The Newsletter plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 8.0.6. This is due to missing or incorrect nonce validation in the main/welcome.php file. This makes it possible for unauthenticated attackers…
*-8.0.6
8.0.7
10/04/2024
Newsletter <= 8.2.0 – IP Spoofing
The Newsletter – Send awesome emails from WordPress plugin for WordPress is vulnerable to IP Address Spoofing in all versions up to, and including, 8.2.0 due to insufficient IP address validation. This makes it possible for unauthenticated attackers…
*-8.2.0
8.2.1
28/03/2024
Newsletter <= 8.0.6 – Cross-Site Request Forgery
The Newsletter – Send awesome emails from WordPress plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 8.0.6. This is due to missing or incorrect nonce validation in the main/welcome.php file.…
*-8.0.6
8.0.7
10/01/2024
Newsletter <= 7.8.9 – Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode
The Newsletter plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'newsletter_form' shortcode in versions up to, and including, 7.8.9 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible…
*-7.8.9
7.9.0
17/08/2023
Newsletter <= 7.6.8 – Reflected Cross-Site Scripting
The Newsletter plugin for WordPress may be vulnerable to Reflected Cross-Site Scripting via the $_SERVER['REQUEST_URI'] parameter in versions up to, and including, 7.6.8 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers…
*-7.6.8
7.6.9
27/03/2023
Newsletter <= 7.4.5 – Authenticated (Admin+) Stored Cross-Site Scripting
The Newsletter plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the preheader_text value in versions up to, and including, 7.4.5 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers with…
[*, 7.4.6)
7.4.6
30/05/2022
Newsletter – Send awesome emails from WordPress <= 7.4.4 – Reflected Cross-Site Scripting
The Newsletter WordPress plugin before 7.4.5 does not sanitize and escape the $_SERVER['REQUEST_URI'] before echoing it back in admin pages. Although this uses addslashes, and most modern browsers automatically URLEncode requests, this is still vulnerable to Reflected XSS…
*-7.4.4
7.4.5
23/05/2022
Newsletter <= 6.8.1 – Reflected Cross-Site Scripting
A Reflected Authenticated Cross-Site Scripting (XSS) vulnerability in the Newsletter plugin before 6.8.2 for WordPress allows remote attackers to trick a victim into submitting a tnpc_render AJAX request containing either JavaScript in an options parameter, or a base64-encoded…
[*, 6.8.2)
6.8.2
03/08/2020
Newsletter <= 6.8.1 – Authenticated PHP Object Injection
Insecure Deserialization in the Newsletter plugin before 6.8.2 for WordPress allows authenticated remote attackers with minimal privileges (such as subscribers) to use the tpnc_render AJAX action to inject arbitrary PHP objects via the options[inline_edits] parameter. NOTE: exploitability depends…
[*, 6.8.2)
6.8.2
02/08/2020
Newsletter <= 6.7.6 – Stored Cross-Site Scripting
The Newsletter plugin for WordPress is vulnerable to Stored Cross-Site Scripting via multiple parameters in versions up to, and including, 6.7.6 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers to inject…
*-6.7.6
6.7.7
12/07/2020
Newsletter <= 6.5.3 – CSV Injection
The Newsletter plugin for WordPress is vulnerable to CSV Injection in versions up to, and including, 6.5.3 by the use of Microsoft Excel DDE function, or to leak data via maliciously injected hyperlinks. This allows non-privileged attackers to…
*-6.5.3
6.5.4
16/03/2020
Newsletter <= 3.8.2 – Open Redirect
The Newsletter plugin is susceptible to an Open Redirect vulnerability. This issue is due to the fact user input it taken, and trusted, without validation. This user input is used when tracking link clicks, via the ‘newsletter/statistics/link.php’ script.…
*-3.8.2
3.8.3
30/03/2015
Newsletter <= 3.2.6 – Reflected Cross-Site Scripting
The Newsletter plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘alert’ parameter in the 'page.php' file in versions up to, and including, 3.2.6 due to insufficient input sanitization and output escaping. This makes it possible…
*-3.2.6
3.2.7
14/05/2013
Extensions également surveillés
WP Commander
Rechercher dans toute la base WordPress
Utilisez la recherche globale pour retrouver une extension, un thème, une CVE ou un identifiant de vulnérabilité.