CVE-2025-3582: Newsletter < 8.8.5 - Admin+ Stored XSS via Form
Published Jun 9, 2025
·Updated
The Newsletter WordPress plugin before 8.85 does not sanitise and escape some of its Form settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfilteredhtml capability is disallowed (for example in multisite setup).
Affected Software
1 affected component
Thenewsletterplugin Newsletter Wordpress<8.8.5
Event History
Jun 9, 2025
CVE Published
via MITRE·06:00 AM
Data Sourced
via MITRE·06:00 AM
DescriptionWeakness
Data Sourced
via NVD·06:15 AM
DescriptionSeverity
Frequently Asked Questions
1
What is the severity of CVE-2025-3582?
CVE-2025-3582 has been classified as a moderate severity vulnerability.
2
How do I fix CVE-2025-3582?
To fix CVE-2025-3582, update the Newsletter WordPress plugin to version 8.8.6 or later.
3
What types of attacks are possible with CVE-2025-3582?
CVE-2025-3582 allows for Stored Cross-Site Scripting (XSS) attacks.
4
Who is affected by CVE-2025-3582?
CVE-2025-3582 affects users of the Newsletter WordPress plugin versions prior to 8.8.6.
5
Can only admin users exploit CVE-2025-3582?
Yes, CVE-2025-3582 can be exploited by high privilege users, such as administrators.