Description
Unauthenticated Cross Site Scripting (XSS) in Newsletter <= 9.3.3 versions.
Published: 2026-08-19
Score: 7.1 High
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability is a classic XSS flaw that allows an unauthenticated attacker to inject arbitrary scripts into the Newsletter plugin’s output; an attacker can craft a URL or manipulate request parameters that the plugin reflects without proper sanitization, enabling them to execute code in the context of any user who views the affected page, potentially leading to cookie theft, defacement, or execution of malicious payloads and compromising user confidentiality and site integrity; the weakness is identified as CWE‑79.

Affected Systems

This issue affects installations of the WordPress Newsletter plugin version 9.3.3 and earlier, and exposes any WordPress site that includes the plugin regardless of user permissions because the vulnerability does not require authentication; it is maintained by Stefano Lissa.

Risk and Exploitability

The CVSS base score of 7.1 classifies it as high severity, and the flaw is exploitable without authentication or special privileges; no EPSS data is available and it has not been listed in the CISA KEV catalog, but the attacker can reach the affected code through any publicly accessible page that loads the Newsletter plugin, making the risk elevated until the plugin is updated

Generated by OpenCVE AI on August 19, 2026 at 19:46 UTC.

Remediation

Vendor Solution

Update the WordPress Newsletter Plugin to the latest available version (at least 9.3.4).


OpenCVE Recommended Actions

  • Apply the vendor patch by upgrading the WordPress Newsletter plugin to version 9.3.4 or later.
  • If an immediate upgrade is not possible, disable the Newsletter plugin until the patch is applied to prevent exposure.
  • Consider implementing a web application firewall or tightening content security policy rules to block XSS attempts while the plugin remains at the vulnerable version.

Generated by OpenCVE AI on August 19, 2026 at 19:46 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 19 Aug 2026 20:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 19 Aug 2026 19:30:00 +0000

Type Values Removed Values Added
First Time appeared Stefanno Lissa
Stefanno Lissa newsletter
Wordpress
Wordpress wordpress
Vendors & Products Stefanno Lissa
Stefanno Lissa newsletter
Wordpress
Wordpress wordpress

Wed, 19 Aug 2026 13:00:00 +0000

Type Values Removed Values Added
Description Unauthenticated Cross Site Scripting (XSS) in Newsletter <= 9.3.3 versions.
Title WordPress Newsletter plugin <= 9.3.3 - Cross Site Scripting (XSS) vulnerability
Weaknesses CWE-79
References
Metrics cvssV3_1

{'score': 7.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L'}


Subscriptions

Stefanno Lissa Newsletter
Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-08-19T19:38:36.483Z

Reserved: 2026-07-27T14:00:08.990Z

Link: CVE-2026-66596

cve-icon Vulnrichment

Updated: 2026-08-19T19:38:31.504Z

cve-icon NVD

Status : Received

Published: 2026-08-19T13:17:50.430

Modified: 2026-08-19T20:17:20.623

Link: CVE-2026-66596

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-19T20:00:05Z

Weaknesses
  • CWE-79

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')