Impact
The Newsletter WordPress plugin prior to version 9.3.7 fails to validate the target URL supplied during a public subscription process. This flaw allows an attacker to supply a malicious redirect URL, resulting in a user’s browser being sent to an arbitrary external site once a subscription is completed. At the same time, the plugin leaks the subscriber token associated with the new record, giving anyone who intercepts the response the ability to access that subscriber’s front‑end actions. The combined effect is a privacy breach and a vector for phishing or other social engineering attacks.
Affected Systems
Any WordPress installation that has Newsletter version 9.3.6 or earlier installed is vulnerable, regardless of site location or host. The vulnerability does not require authentication; it is triggered whenever a public subscription request is made. No specific domain data is available, but the risk applies to all publicly accessible deployments of the plugin.
Risk and Exploitability
The EPSS score of less than 1% indicates that exploitation likelihood is very low at the time of analysis, and the issue is not listed in the CISA KEV catalog. The CVSS score of 5.3 suggests moderate severity. The attack path is straightforward: an attacker creates a subscription link that points the Newsletter redirect endpoint to a chosen malicious URL. When an unsuspecting user clicks this link, the site redirects to the attacker’s domain and returns the subscriber token in the response. Because the flaw is unauthenticated, any visitor can be impacted, but practical exploitation depends on successful social‑engineering to prompt a subscription.
OpenCVE Enrichment