Impact
The vulnerability exists in the Newsletter plugin for WordPress and allows an attacker to inject arbitrary JavaScript through the 'nn' query parameter. Because the plugin does not sanitize or escape this value, the script is reflected into pages that the administrator views after clicking a crafted link. Successful exploitation requires the victim to be a logged‑in administrator, as the antibot check auto‑passes for authenticated users, routing the unsanitized payload through the administrator‑visible output branch of dienow().
Affected Systems
The affected product is the Newsletter – Send awesome emails from WordPress plugin from vendor satollo. All versions up to and including 9.3.8 are vulnerable. Any WordPress installation that has this plugin installed and a vulnerable version is at risk.
Risk and Exploitability
The CVSS score of 6.1 indicates a moderate severity. The EPSS score of less than 1 % suggests a low likelihood of exploitation in the wild, and the vulnerability is not listed in CISA's KEV catalog. Exploitation requires the attacker to lure an administrator to click on a URL containing the malicious 'nn' value; the attacker then can run arbitrary scripts within the admin’s browser context.
OpenCVE Enrichment