Impact
This vulnerability is a stored X‑Scripting flaw in the Newsletters Lite WordPress plugin. The post_thumbnail() method concatenates the user‑controlled 'link' shortcode attribute directly into an href attribute without sanitization or escaping. An authenticated attacker who has at least contributor privileges can inject arbitrary JavaScript that will execute whenever a recipient views a newsletter page. The impact includes session hijacking, credential theft, defacement, and other client‑side abuses, as the scripts run in the context of the logged‑in user.
Affected Systems
The flaw exists in the Newsletters Lite plugin for WordPress, for all releases up to and including version 4.15. Users of these versions are affected; newer releases are not known to contain the issue.
Risk and Exploitability
The vulnerability has a CVSS score of 6.4, indicating moderate severity, and the EPSS score is less than 1%, meaning the likelihood of exploitation is currently low. The issue is not listed in the CISA Known‑Exploited Vulnerabilities catalog. Exploitation requires attacker authentication with contributor‑level access and the ability to edit or create newsletter content. There are no known public exploits; the attack vector is thus limited to attackers who can gain or already possess sufficient privileges within the WordPress instance.
OpenCVE Enrichment