Impact
The Newsletters plugin for WordPress suffers from a stored cross‑site scripting flaw caused by insufficient input sanitization and output escaping in its logging functionality. An unauthenticated attacker can inject malicious scripts into logs that are subsequently served to anyone who views a page containing the injected entry, leading to defacement, session hijacking, or other client‑side attacks.
Affected Systems
WordPress sites running the Newsletters plugin version 4.9.9.7 or older are vulnerable. The flaw applies to all releases up to and including 4.9.9.7 and affects the logging component accessible via the plugin’s settings and logs pages.
Risk and Exploitability
The CVSS score of 7.2 indicates high severity, while the EPSS score of less than 1% suggests a very low current exploitation probability. The vulnerability is not listed in the CISA KEV catalog. The likely attack vector is an unauthenticated user accessing a log page through which arbitrary script is injected; any user who then loads that page would have the injected code executed in their browser. The impact is client‑side compromise, potentially leading to credential theft, phishing, or defacement.
OpenCVE Enrichment
EUVD