<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:webfeeds="http://webfeeds.org/rss/1.0"><channel><title>The Newsletter – Send Awesome Emails From WordPress (&lt;= 9.4.0) - CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/products/the-newsletter--send-awesome-emails-from-wordpress--9.4.0/</link><description>Trending threats, MITRE ATT&amp;CK coverage, and detection metadata. Fed continuously.</description><generator>Hugo</generator><language>en</language><managingEditor>hello@craftedsignal.io</managingEditor><webMaster>hello@craftedsignal.io</webMaster><lastBuildDate>Fri, 02 Oct 2026 08:24:11 +0000</lastBuildDate><atom:link href="https://feed.craftedsignal.io/products/the-newsletter--send-awesome-emails-from-wordpress--9.4.0/feed.xml" rel="self" type="application/rss+xml"/><image><url>https://feed.craftedsignal.io/favicon-32x32.png</url><title>CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/</link><width>32</width><height>32</height></image><webfeeds:icon>https://feed.craftedsignal.io/favicon.svg</webfeeds:icon><item><title>Stored Cross-Site Scripting in The Newsletter Plugin for WordPress</title><link>https://feed.craftedsignal.io/briefs/2026-10-newsletter-xss/</link><pubDate>Fri, 02 Oct 2026 08:24:11 +0000</pubDate><author>hello@craftedsignal.io</author><guid isPermaLink="true">https://feed.craftedsignal.io/briefs/2026-10-newsletter-xss/</guid><description>The Newsletter plugin for WordPress versions &lt;= 9.4.0 is vulnerable to Stored XSS via the 'np1' parameter, allowing unauthenticated attackers to execute arbitrary scripts due to missing input sanitization and endpoint security controls.</description><content:encoded><![CDATA[<p>The Newsletter - Send awesome emails from WordPress plugin is affected by a Stored Cross-Site Scripting (XSS) vulnerability (CVE-2026-96566) in all versions up to and including 9.4.0. The vulnerability exists due to insufficient sanitization and output escaping of the 'np1' custom field parameter. Because the plugin's subscription endpoint (na=sa) fails to implement nonce verification, capability checks, or CAPTCHA, unauthenticated attackers can successfully submit malicious payloads. An attacker can bypass standard WordPress email validation by injecting the '{profile_1}' placeholder into the local part of the email address, which the 'is_email()' function permits. Once the payload is stored, it executes in the browser of any user who views the affected page, leading to potential session hijacking or further administrative actions if an administrator views the data.</p>
<h2 id="impact">Impact</h2>
<p>Successful exploitation allows unauthenticated attackers to inject arbitrary web scripts into pages. This poses a high risk to WordPress installations by potentially facilitating account takeover or unauthorized actions if administrative users view the injected content. The vulnerability is widespread among sites utilizing this plugin for email management.</p>
<h2 id="recommendation">Recommendation</h2>
<p>Update the &quot;The Newsletter - Send awesome emails from WordPress&quot; plugin to a version released after 9.4.0 that contains the input sanitization patches. Monitor web server logs for HTTP POST requests to the subscription endpoint containing suspicious characters or script tags in the email or 'np1' parameters.</p>
<h2 id="attack-chain">Attack Chain</h2>
<ol>
<li>Attacker identifies a target WordPress site using the vulnerable plugin.</li>
<li>Attacker crafts a malicious payload containing JavaScript, wrapping it in an email-like structure.</li>
<li>Attacker uses the '{profile_1}' placeholder within the email field to bypass 'is_email()' validation.</li>
<li>Attacker includes the malicious script within the 'np1' custom field parameter.</li>
<li>Attacker submits a POST request to the 'na=sa' subscription endpoint.</li>
<li>The plugin improperly sanitizes the 'np1' input and stores it in the WordPress database.</li>
<li>A target user (e.g., an administrator) views the page where the stored script is rendered.</li>
<li>The malicious script executes in the victim's browser session.</li>
</ol>
]]></content:encoded><category domain="severity">high</category><category domain="type">advisory</category><category>web-application</category><category>xss</category><category>wordpress</category></item></channel></rss>