Skip to content
Threat Feed
high advisory

Stored Cross-Site Scripting in The Newsletter Plugin for WordPress

The Newsletter plugin for WordPress versions <= 9.4.0 is vulnerable to Stored XSS via the 'np1' parameter, allowing unauthenticated attackers to execute arbitrary scripts due to missing input sanitization and endpoint security controls.

CVE search metadata

CVE search record: CVE-2026-96566. Severity: high. CVSS: 7.2. KEV: no. Product: The Newsletter – Send awesome emails from WordPress (<= 9.4.0). Brief: Stored Cross-Site Scripting in The Newsletter Plugin for WordPress. Brief link: https://feed.craftedsignal.io/briefs/2026-10-newsletter-xss/

The Newsletter - Send awesome emails from WordPress plugin is affected by a Stored Cross-Site Scripting (XSS) vulnerability (CVE-2026-96566) in all versions up to and including 9.4.0. The vulnerability exists due to insufficient sanitization and output escaping of the 'np1' custom field parameter. Because the plugin's subscription endpoint (na=sa) fails to implement nonce verification, capability checks, or CAPTCHA, unauthenticated attackers can successfully submit malicious payloads. An attacker can bypass standard WordPress email validation by injecting the '{profile_1}' placeholder into the local part of the email address, which the 'is_email()' function permits. Once the payload is stored, it executes in the browser of any user who views the affected page, leading to potential session hijacking or further administrative actions if an administrator views the data.

Impact

Successful exploitation allows unauthenticated attackers to inject arbitrary web scripts into pages. This poses a high risk to WordPress installations by potentially facilitating account takeover or unauthorized actions if administrative users view the injected content. The vulnerability is widespread among sites utilizing this plugin for email management.

Recommendation

Update the "The Newsletter - Send awesome emails from WordPress" plugin to a version released after 9.4.0 that contains the input sanitization patches. Monitor web server logs for HTTP POST requests to the subscription endpoint containing suspicious characters or script tags in the email or 'np1' parameters.

Attack Chain

  1. Attacker identifies a target WordPress site using the vulnerable plugin.
  2. Attacker crafts a malicious payload containing JavaScript, wrapping it in an email-like structure.
  3. Attacker uses the '{profile_1}' placeholder within the email field to bypass 'is_email()' validation.
  4. Attacker includes the malicious script within the 'np1' custom field parameter.
  5. Attacker submits a POST request to the 'na=sa' subscription endpoint.
  6. The plugin improperly sanitizes the 'np1' input and stores it in the WordPress database.
  7. A target user (e.g., an administrator) views the page where the stored script is rendered.
  8. The malicious script executes in the victim's browser session.

Immediate actions

Update The Newsletter plugin to a patched version post-9.4.0

IT Operations 48h

Threat Hunt

Search logs for 'na=sa' and 'np1=' to identify potential previous exploitation attempts

T1190 high high confidence hunt now

Data: webserver access logs

Mitigations

Upgrade plugin to latest secure version

immediate IT Operations

CVE-2026-96566

Detection coverage 1

Detect CVE-2026-96566 Exploitation - Stored XSS Attempt via Subscription Endpoint

high

Detects exploitation attempts against the Newsletter plugin where the 'np1' parameter contains script tags or HTML event handlers.

sigma tactics: execution, initial_access techniques: T1059.007 sources: webserver

Detection queries are available on the platform. Get full rules →