Sceawere
Vulnerability Detail
CVE-2026-96566UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
Stored XSS in Newsletter Plugin
Vulnerability Metadata
- Severity
- High
- Score / CVSS
- 7.2
- Creation Date
- 15h ago
- Vendor
- satollo
- Product
- Newsletter – Send awesome emails from WordPress
- Attack Type
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
- Vector String
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N
- Attack Complexity
- LOW
Narrative and Response
Description
The Newsletter – Send awesome emails from WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'np1' Custom Field Parameter in all versions up to, and including, 9.4.0 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. The subscription endpoint (na=sa) requires no nonce, no capability check, and no CAPTCHA, and the payload can be smuggled past email-address validation by embedding the {profile_1} placeholder in the local part of the submitted address, since WordPress's is_email() permits curly braces there.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "7.2",
"pubDate": "2026-10-02T08:17:04.117Z",
"pubdate": "2026-10-02T08:17:04.117Z",
"executiveSummary": "The Newsletter – Send awesome emails from WordPress plugin is susceptible to a Stored Cross-Site Scripting (XSS) vulnerability in all versions up to and including 9.4.0.\nThe vulnerability originates from insufficient input sanitization and inadequate output escaping within the 'np1' custom field parameter, which is processed by the plugin's subscription endpoint (na=sa).\nThis flaw allows unauthenticated remote attackers to inject malicious JavaScript payloads into the WordPress database. When these stored scripts are rendered in the administrative dashboard or front-end pages, they execute within the context of the victim's browser session.\nThe attack vector is particularly severe because the affected endpoint lacks critical security controls, including nonces for CSRF protection, capability checks for authorization, and CAPTCHA validation.\nFurthermore, the plugin's email validation logic, which relies on the WordPress is_email() function, fails to block payloads containing curly braces, allowing attackers to smuggle XSS vectors through the {profile_1} placeholder.\nSuccessful exploitation allows attackers to perform unauthorized actions on behalf of authenticated administrators, steal session cookies, or redirect users to malicious domains, effectively compromising the integrity and security of the WordPress installation.",
"technicalDetails": "The vulnerability resides in the subscription processing logic of the Newsletter plugin, specifically within the handling of custom field data passed through the 'np1' parameter via the (na=sa) endpoint.\nThe root cause is a dual failure: the application fails to properly sanitize user-supplied input before storing it in the database and neglects to apply contextual output encoding when rendering that data back to the user interface.\nThe attack flow begins when an unauthenticated actor sends a crafted POST or GET request to the subscription endpoint. By embedding an XSS payload within the local part of the email address field—specifically leveraging the fact that the application's email validation logic permits curly braces by design—the attacker bypasses standard input filters.\nBecause the 'np1' parameter is directly associated with a user profile custom field, the malicious script is persisted in the WordPress database.\nWhen a user, typically an administrator or a user with profile-viewing capabilities, accesses a page where this custom field data is displayed, the browser interprets the stored string as executable code. This results in the execution of arbitrary JavaScript within the victim's security context.\nThe lack of a nonce allows this entire process to be triggered without requiring an existing session or CSRF protection, facilitating automated exploitation by remote attackers.\nSince the plugin does not verify if the requestor possesses administrative privileges, the entry point remains completely exposed to the public internet.\nThe impact of this stored XSS is substantial; it enables full-scale account takeover, the modification of site configurations, or the silent exfiltration of sensitive site data by injecting scripts that monitor user interactions or manipulate form inputs in real-time.\nThe exploitation is trivial due to the total absence of security headers or server-side restrictions on the subscription endpoint, making it an ideal target for mass-automated malicious injection campaigns."
}