Description
Unauthenticated Cross Site Scripting (XSS) in Email Subscribers & Newsletters <= 5.9.33 versions.
Published: 2026-08-31
Score: 7.1 High
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

An unauthenticated XSS vulnerability allows an attacker to inject arbitrary client‑side scripts into web pages served by the plugin. While the flaw does not disclose server‑side data directly, the injected code runs in the browser context of any visitor, potentially leading to cookie theft, session hijacking, defacement, or the delivery of malicious payloads. The weakness lies in the lack of proper output encoding or sanitization when rendering user‑controlled content.

Affected Systems

WordPress sites running the Icegram Email Subscribers & Newsletters plugin version 5.9.33 or earlier are impacted. No additional vendor or version details beyond the listed product are provided.

Risk and Exploitability

The common vulnerability scoring system assigns a score of 7.1, indicating a high severity. The EPSS metric is not available, so the current probability of exploitation is unknown from that source. The vulnerability is not present in the CISA KEV catalog. Because the bug is unauthenticated, any user who can submit input to the plugin can trigger the exploit, and the payload executes in the victim’s browser, making the attack vector broad but not requiring privileged access.

Generated by OpenCVE AI on August 31, 2026 at 21:26 UTC.

Remediation

Vendor Solution

Update the WordPress Email Subscribers & Newsletters Plugin to the latest available version (at least 5.9.34).


OpenCVE Recommended Actions

  • Install the latest WordPress Email Subscribers & Newsletters plugin (version 5.9.34 or higher).
  • If updating is not immediately possible, remove or disable the plugin to prevent exploitation until a fix is applied.
  • Apply a strict content security policy that disallows inline scripts and mitigates the impact of any remaining XSS payloads while remediation is underway.

Generated by OpenCVE AI on August 31, 2026 at 21:26 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 31 Aug 2026 22:45:00 +0000

Type Values Removed Values Added
First Time appeared Icegram
Icegram email Subscribers & Newsletters
Wordpress
Wordpress wordpress
Vendors & Products Icegram
Icegram email Subscribers & Newsletters
Wordpress
Wordpress wordpress

Mon, 31 Aug 2026 20:45:00 +0000

Type Values Removed Values Added
Description Unauthenticated Cross Site Scripting (XSS) in Email Subscribers & Newsletters <= 5.9.33 versions.
Title WordPress Email Subscribers & Newsletters plugin <= 5.9.33 - Cross Site Scripting (XSS) vulnerability
Weaknesses CWE-79
References
Metrics cvssV3_1

{'score': 7.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L'}


Subscriptions

Icegram Email Subscribers & Newsletters
Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-08-31T20:30:43.061Z

Reserved: 2026-08-26T17:33:24.197Z

Link: CVE-2026-81290

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-08-31T21:17:49.930

Modified: 2026-08-31T21:17:49.930

Link: CVE-2026-81290

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-31T22:30:06Z

Weaknesses
  • CWE-79

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')