CVE-2025-3584: Newsletter < 8.8.2 - Admin+ Stored XSS via Subscription
The Newsletter WordPress plugin before 8.8.2 does not sanitise and escape some of its Subscription settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfilteredhtml capability is disallowed (for example in multisite setup).
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-3584?
CVE-2025-3584 is classified as a high severity vulnerability due to the potential for Stored Cross-Site Scripting attacks by privileged users.
How do I fix CVE-2025-3584?
To fix CVE-2025-3584, update the WordPress Newsletter plugin to version 8.8.2 or later.
Who is affected by CVE-2025-3584?
CVE-2025-3584 affects users of the WordPress Newsletter plugin prior to version 8.8.2.
What type of attack is associated with CVE-2025-3584?
CVE-2025-3584 is associated with Stored Cross-Site Scripting (XSS) attacks.
What can happen if CVE-2025-3584 is exploited?
If exploited, CVE-2025-3584 can allow high privilege users to inject malicious scripts that may compromise website security.