{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/products/the-newsletter--send-awesome-emails-from-wordpress--9.4.0/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:thenewsletterplugin:newsletter:*:*:*:*:*:wordpress:*:*"],"_cs_cves":[{"cvss":7.2,"id":"CVE-2026-96566"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["The Newsletter – Send awesome emails from WordPress (\u003c= 9.4.0)"],"_cs_severities":["high"],"_cs_tags":["web-application","xss","wordpress"],"_cs_type":"advisory","_cs_vendors":["WordPress"],"content_html":"\u003cp\u003eThe Newsletter - Send awesome emails from WordPress plugin is affected by a Stored Cross-Site Scripting (XSS) vulnerability (CVE-2026-96566) in all versions up to and including 9.4.0. The vulnerability exists due to insufficient sanitization and output escaping of the 'np1' custom field parameter. Because the plugin's subscription endpoint (na=sa) fails to implement nonce verification, capability checks, or CAPTCHA, unauthenticated attackers can successfully submit malicious payloads. An attacker can bypass standard WordPress email validation by injecting the '{profile_1}' placeholder into the local part of the email address, which the 'is_email()' function permits. Once the payload is stored, it executes in the browser of any user who views the affected page, leading to potential session hijacking or further administrative actions if an administrator views the data.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation allows unauthenticated attackers to inject arbitrary web scripts into pages. This poses a high risk to WordPress installations by potentially facilitating account takeover or unauthorized actions if administrative users view the injected content. The vulnerability is widespread among sites utilizing this plugin for email management.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cp\u003eUpdate the \u0026quot;The Newsletter - Send awesome emails from WordPress\u0026quot; plugin to a version released after 9.4.0 that contains the input sanitization patches. Monitor web server logs for HTTP POST requests to the subscription endpoint containing suspicious characters or script tags in the email or 'np1' parameters.\u003c/p\u003e\n\u003ch2 id=\"attack-chain\"\u003eAttack Chain\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eAttacker identifies a target WordPress site using the vulnerable plugin.\u003c/li\u003e\n\u003cli\u003eAttacker crafts a malicious payload containing JavaScript, wrapping it in an email-like structure.\u003c/li\u003e\n\u003cli\u003eAttacker uses the '{profile_1}' placeholder within the email field to bypass 'is_email()' validation.\u003c/li\u003e\n\u003cli\u003eAttacker includes the malicious script within the 'np1' custom field parameter.\u003c/li\u003e\n\u003cli\u003eAttacker submits a POST request to the 'na=sa' subscription endpoint.\u003c/li\u003e\n\u003cli\u003eThe plugin improperly sanitizes the 'np1' input and stores it in the WordPress database.\u003c/li\u003e\n\u003cli\u003eA target user (e.g., an administrator) views the page where the stored script is rendered.\u003c/li\u003e\n\u003cli\u003eThe malicious script executes in the victim's browser session.\u003c/li\u003e\n\u003c/ol\u003e\n","date_modified":"2026-10-02T08:24:11Z","date_published":"2026-10-02T08:24:11Z","id":"https://feed.craftedsignal.io/briefs/2026-10-newsletter-xss/","summary":"The Newsletter plugin for WordPress versions \u003c= 9.4.0 is vulnerable to Stored XSS via the 'np1' parameter, allowing unauthenticated attackers to execute arbitrary scripts due to missing input sanitization and endpoint security controls.","title":"Stored Cross-Site Scripting in The Newsletter Plugin for WordPress","url":"https://feed.craftedsignal.io/briefs/2026-10-newsletter-xss/"}],"language":"en","title":"CraftedSignal Threat Feed - The Newsletter – Send Awesome Emails From WordPress (\u003c= 9.4.0)","version":"https://jsonfeed.org/version/1.1"}