Impact
The Tribulant Software Newsletters plugin (Newsletters‑Lite) for WordPress contains an improper neutralization of input during web page generation, which allows reflected cross‑site scripting (XSS). When a vulnerable parameter is processed, unsanitized user input is echoed back into the response page, enabling a malicious actor to inject executable scripts. These scripts run in the context of the victim’s browser, allowing cookie theft, session hijacking, or phishing attacks.
Affected Systems
The flaw affects the Tribulant Software Newsletters plugin for WordPress, versions up to and including 4.14. Any WordPress site that has installed this plugin without upgrading to a later release is vulnerable.
Risk and Exploitability
The base CVSS score of 7.1 indicates a moderate‑to‑high impact risk, while the EPSS score of less than 1% suggests exploitation is relatively unlikely but not impossible. The vulnerability is not listed in the CISA KEV catalog. Based on the description, it is inferred that an attacker can trigger the reflected XSS by providing a victim with a specially crafted URL or link that contains the malicious payload; no local‑only restrictions are documented.
OpenCVE Enrichment