WPHizmet

Eklenti güvenlik geçmişi

Newsletter güvenlik açıkları

ABD Ulusal Güvenlik Açığı Veritabanı’nda (NVD) Newsletter – Send awesome emails from WordPress eklentisi için 19 açık kaydı bulunuyor; en yenisi 2 Ekim 2026 tarihli. Bunların 3 tanesi kritik veya yüksek önemde, 12 tanesi oturum açmadan istismar edilebiliyor. Güncel sürüm 9.4.7.

Toplam kayıt
19
Kritik veya yüksek
3
Oturumsuz istismar
12
Son kayıt
2 Ekim 2026

Bilinen açık kayıtları

En yeniden eskiye. Her kaydın özgün metni NVD’de.

  • CVE-2026-96566Yüksek · 7,22 Ekim 2026

    depolanmış siteler arası betik çalıştırma (XSS)

    Etkilenen sürümler: 9.4.0 ve öncesi · Oturum açmadan istismar edilebilir

    The Newsletter – Send awesome emails from WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'np1' Custom Field Parameter in all versions up to, and including, 9.4.0 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. The subscription endpoint (na=sa) requires no nonce, no capability check, and no CAPTCHA, and the payload can be smuggled past email-address validation by embedding the {profile_1} placeholder in the local part of the submitted address, since WordPress's is_email() permits curly braces there.

    Türkçe kayıt ve ne yapmalı
  • CVE-2026-92537Orta · 5,31 Ekim 2026

    güvenlik

    Etkilenen sürümler: 9.3.9 ve öncesi · Oturum açmadan istismar edilebilir

    The Newsletter – Send awesome emails from WordPress plugin for WordPress is vulnerable to Insufficiently Protected Credentials in all versions up to, and including, 9.3.9 The plugin's public click-tracking REST route `/tnp/l/` is registered with `permission_callback => '__return_true'` and, upon receiving a valid keyed-MD5 signature, calls `set_user_cookie()`, which emits a `Set-Cookie: newsletter=<id>-<raw_token>` response header to the requester because the subscriber object loaded via `get_user()` lacks the `_trusted` property, causing `get_user_key()` to return the raw token column value instead of its MD5-masked variant. This makes it possible for unauthenticated attackers who obtain any signed click-tracking URL for a target subscriber to receive that subscriber's permanent raw authentication cookie, which they can then use to export the subscriber's full PII record via the JSON profile-export endpoint (`?na=px`), rewrite the subscriber's stored profile (`?na=ps`), and silently unsubscribe the subscriber via the RFC-8058 one-click endpoint (`?na=ocu`), none of which require a nonce, password, or email challenge. Signed tracking URLs are embedded in every external link of every newsletter delivered to a subscriber, carry no timestamp, and never expire until the site's relink key rotates, meaning that any party who observes such a URL — through a forwarded email, a shared inbox, a mail-gateway log, or Referer headers on the redirect target, which has no Referrer-Policy se

  • CVE-2026-90981Orta · 6,118 Eylül 2026

    yansıtılan siteler arası betik çalıştırma (XSS)

    Etkilenen sürümler: 9.3.8 ve öncesi · Oturum açmadan istismar edilebilir

    The Newsletter – Send awesome emails from WordPress plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'nn' parameter in all versions up to, and including, 9.3.8 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link. Successful exploitation requires the victim to be a logged-in administrator, as the antibot check auto-passes for authenticated users, routing the unsanitized payload through the administrator-visible output branch of dienow().

  • CVE-2026-86824Orta · 4,817 Eylül 2026

    güvenlik

    Etkilenen sürümler: 9.3.8 öncesi · Oturum açmadan istismar edilebilir

    The Newsletter WordPress plugin before 9.3.8 does not generate its email tracking signing key with sufficient entropy and signs its tracking links with an unkeyed hash, allowing an unauthenticated attacker who recovers that key offline to forge tracking links, obtain any subscriber's session token, and read and modify that subscriber's stored personal data.

  • CVE-2026-86823Orta · 5,316 Eylül 2026

    açık yönlendirme

    Etkilenen sürümler: 9.3.7 öncesi · Oturum açmadan istismar edilebilir

    The Newsletter WordPress plugin before 9.3.7 does not validate the destination of the redirect performed after a public subscription action, allowing unauthenticated attackers to redirect users to arbitrary external sites and to disclose a subscriber token that grants access to that subscriber record's front-end actions.

  • CVE-2026-66596Yüksek · 7,119 Ağustos 2026

    siteler arası betik çalıştırma (XSS)

    Etkilenen sürümler: 9.3.3 ve öncesi · Oturum açmadan istismar edilebilir

    Unauthenticated Cross Site Scripting (XSS) in Newsletter <= 9.3.3 versions.

  • CVE-2026-1051Orta · 4,320 Ocak 2026

    siteler arası istek sahteciliği (CSRF)

    Etkilenen sürümler: 9.1.0 ve öncesi · Oturum açmadan istismar edilebilir

    The Newsletter – Send awesome emails from WordPress plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 9.1.0. This is due to missing or incorrect nonce validation on the hook_newsletter_action() function. This makes it possible for unauthenticated attackers to unsubscribe newsletter subscribers via a forged request granted they can trick a logged-in user into performing an action such as clicking on a link.

  • CVE-2025-67999Yüksek · 7,616 Aralık 2025

    SQL enjeksiyonu

    Etkilenen sürümler: 9.0.9 ve öncesi

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Stefano Lissa Newsletter newsletter allows Blind SQL Injection.This issue affects Newsletter: from n/a through <= 9.0.9.

  • CVE-2025-3582Orta · 4,89 Haziran 2025

    depolanmış siteler arası betik çalıştırma (XSS)

    Etkilenen sürümler: 8.85 öncesi

    The Newsletter WordPress plugin before 8.85 does not sanitise and escape some of its Form settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).

  • CVE-2025-3581Orta · 4,89 Haziran 2025

    depolanmış siteler arası betik çalıştırma (XSS)

    Etkilenen sürümler: 8.8.5 öncesi

    The Newsletter WordPress plugin before 8.8.5 does not validate and escape some of its Widget options before outputting them back in a page/post where the block is embed, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).

  • CVE-2025-3584Orta · 4,83 Haziran 2025

    depolanmış siteler arası betik çalıştırma (XSS)

    Etkilenen sürümler: 8.8.2 öncesi

    The Newsletter WordPress plugin before 8.8.2 does not sanitise and escape some of its Subscription settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).

  • CVE-2025-3583Orta · 4,85 Mayıs 2025

    depolanmış siteler arası betik çalıştırma (XSS)

    Etkilenen sürümler: 8.7.1 öncesi

    The Newsletter WordPress plugin before 8.7.1 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).

  • CVE-2024-5317Orta · 6,15 Haziran 2024

    depolanmış siteler arası betik çalıştırma (XSS)

    Etkilenen sürümler: 8.3.4 ve öncesi · Oturum açmadan istismar edilebilir

    The Newsletter plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'np1' parameter in all versions up to, and including, 8.3.4 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

  • CVE-2024-30522Orta · 5,317 Mayıs 2024

    kimlik doğrulama atlatma

    Etkilenen sürümler: 8.2.0 ve öncesi · Oturum açmadan istismar edilebilir

    Authentication Bypass by Spoofing vulnerability in Stefano Lissa & The Newsletter Team Newsletter allows Functionality Bypass.This issue affects Newsletter: from n/a through 8.2.0.

  • CVE-2024-31434Orta · 5,415 Nisan 2024

    siteler arası istek sahteciliği (CSRF)

    Etkilenen sürümler: 8.0.6 ve öncesi · Oturum açmadan istismar edilebilir

    Cross-Site Request Forgery (CSRF) vulnerability in Stefano Lissa & The Newsletter Team Newsletter.This issue affects Newsletter: from n/a through 8.0.6.

  • CVE-2023-4772Orta · 5,47 Eylül 2023

    depolanmış siteler arası betik çalıştırma (XSS)

    Etkilenen sürümler: 7.8.9 ve öncesi

    The Newsletter plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'newsletter_form' shortcode in versions up to, and including, 7.8.9 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers with contributor-level and above permissions to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

  • CVE-2023-27922Orta · 6,123 Mayıs 2023

    siteler arası betik çalıştırma (XSS)

    Etkilenen sürümler: Kayıtta belirtilmemiş · Oturum açmadan istismar edilebilir

    Cross-site scripting vulnerability in Newsletter versions prior to 7.6.9 allows a remote unauthenticated attacker to inject an arbitrary script.

  • CVE-2022-1889Orta · 4,820 Haziran 2022

    depolanmış siteler arası betik çalıştırma (XSS)

    Etkilenen sürümler: 7.4.6 öncesi

    The Newsletter WordPress plugin before 7.4.6 does not escape and sanitise the preheader_text setting, which could allow high privilege users to perform Stored Cross-Site Scripting attacks when the unfilteredhtml is disallowed

  • CVE-2022-1756Orta · 6,113 Haziran 2022

    yansıtılan siteler arası betik çalıştırma (XSS)

    Etkilenen sürümler: 7.4.5 öncesi · Oturum açmadan istismar edilebilir

    The Newsletter WordPress plugin before 7.4.5 does not sanitize and escape the $_SERVER['REQUEST_URI'] before echoing it back in admin pages. Although this uses addslashes, and most modern browsers automatically URLEncode requests, this is still vulnerable to Reflected XSS in older browsers such as Internet Explorer 9 or below.

Kaynak: NVD (kamu malı veri) ve WordPress.org eklenti dizini. Kayıtlar eklentinin WordPress.org adresi veya tam adıyla eşleştirilir. Veri 7 Ekim 2026 itibarıyla.