Impact
The Newsletters‑lite plugin for WordPress contains an improper neutralization of input during web page generation that permits stored cross‑site scripting. The flaw allows an attacker to submit untrusted data that the plugin stores and later serves to other visitors. The stored input is rendered in the context of the site, meaning any JavaScript injected by an attacker will be executed in the browser processes of users who view the affected page.
Affected Systems
All instances of Tribulant Software’s Newsletters‑lite plugin with a version number 4.12 or earlier are vulnerable. The issue applies to every deployment of the plugin at those or earlier versions, regardless of WordPress core version or hosting environment.
Risk and Exploitability
The published CVSS score of 6.5 places the vulnerability in the medium severity range. The EPSS score is less than one percent, indicating a low probability of widespread exploitation at the time of analysis. The vulnerability requires an attacker to submit input that the plugin stores and later serves; it is a client‑side weakness that affects only the victim’s browser session. Attackers may use social engineering or compromise a trusted user’s submission to inject the malicious payload.
OpenCVE Enrichment