Stored Cross-Site Scripting in The Newsletter Plugin for WordPress
The Newsletter plugin for WordPress versions <= 9.4.0 is vulnerable to Stored XSS via the 'np1' parameter, allowing unauthenticated attackers to execute arbitrary scripts due to missing input sanitization and endpoint security controls.
CVE search metadata
CVE search record: CVE-2026-96566. Severity: high. CVSS: 7.2. KEV: no. Product: The Newsletter – Send awesome emails from WordPress (<= 9.4.0). Brief: Stored Cross-Site Scripting in The Newsletter Plugin for WordPress. Brief link: https://feed.craftedsignal.io/briefs/2026-10-newsletter-xss/
The Newsletter - Send awesome emails from WordPress plugin is affected by a Stored Cross-Site Scripting (XSS) vulnerability (CVE-2026-96566) in all versions up to and including 9.4.0. The vulnerability exists due to insufficient sanitization and output escaping of the 'np1' custom field parameter. Because the plugin's subscription endpoint (na=sa) fails to implement nonce verification, capability checks, or CAPTCHA, unauthenticated attackers can successfully submit malicious payloads. An attacker can bypass standard WordPress email validation by injecting the '{profile_1}' placeholder into the local part of the email address, which the 'is_email()' function permits. Once the payload is stored, it executes in the browser of any user who views the affected page, leading to potential session hijacking or further administrative actions if an administrator views the data.
Impact
Successful exploitation allows unauthenticated attackers to inject arbitrary web scripts into pages. This poses a high risk to WordPress installations by potentially facilitating account takeover or unauthorized actions if administrative users view the injected content. The vulnerability is widespread among sites utilizing this plugin for email management.
Recommendation
Update the "The Newsletter - Send awesome emails from WordPress" plugin to a version released after 9.4.0 that contains the input sanitization patches. Monitor web server logs for HTTP POST requests to the subscription endpoint containing suspicious characters or script tags in the email or 'np1' parameters.
Attack Chain
- Attacker identifies a target WordPress site using the vulnerable plugin.
- Attacker crafts a malicious payload containing JavaScript, wrapping it in an email-like structure.
- Attacker uses the '{profile_1}' placeholder within the email field to bypass 'is_email()' validation.
- Attacker includes the malicious script within the 'np1' custom field parameter.
- Attacker submits a POST request to the 'na=sa' subscription endpoint.
- The plugin improperly sanitizes the 'np1' input and stores it in the WordPress database.
- A target user (e.g., an administrator) views the page where the stored script is rendered.
- The malicious script executes in the victim's browser session.
Immediate actions
Update The Newsletter plugin to a patched version post-9.4.0
Threat Hunt
Search logs for 'na=sa' and 'np1=' to identify potential previous exploitation attempts
Data: webserver access logs
Mitigations
Upgrade plugin to latest secure version
CVE-2026-96566
Detection coverage 1
Detect CVE-2026-96566 Exploitation - Stored XSS Attempt via Subscription Endpoint
highDetects exploitation attempts against the Newsletter plugin where the 'np1' parameter contains script tags or HTML event handlers.
Detection queries are available on the platform. Get full rules →