Product
The Newsletter plugin for WordPress versions <= 9.4.0 is vulnerable to Stored XSS via the 'np1' parameter, allowing unauthenticated attackers to execute arbitrary scripts due to missing input sanitization and endpoint security controls.