Impact
The vulnerability is a classic XSS flaw that allows an unauthenticated attacker to inject arbitrary scripts into the Newsletter plugin’s output; an attacker can craft a URL or manipulate request parameters that the plugin reflects without proper sanitization, enabling them to execute code in the context of any user who views the affected page, potentially leading to cookie theft, defacement, or execution of malicious payloads and compromising user confidentiality and site integrity; the weakness is identified as CWE‑79.
Affected Systems
This issue affects installations of the WordPress Newsletter plugin version 9.3.3 and earlier, and exposes any WordPress site that includes the plugin regardless of user permissions because the vulnerability does not require authentication; it is maintained by Stefano Lissa.
Risk and Exploitability
The CVSS base score of 7.1 classifies it as high severity, and the flaw is exploitable without authentication or special privileges; no EPSS data is available and it has not been listed in the CISA KEV catalog, but the attacker can reach the affected code through any publicly accessible page that loads the Newsletter plugin, making the risk elevated until the plugin is updated
OpenCVE Enrichment