CVE-2026-66596: WordPress Newsletter plugin <= 9.3.3 - Cross Site Scripting (XSS) vulnerability
Unauthenticated Cross Site Scripting (XSS) in Newsletter <= 9.3.3 versions.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
WordPress Newsletter Pluginto a version that resolves this vulnerability.Fixed in 9.3.4
Event History
Frequently Asked Questions
Who can exploit this vulnerability?
The vulnerability is described as unauthenticated, so an attacker does not need a WordPress account or plugin-specific credentials. Exploitation still requires user interaction, as indicated by the UI:R vector.
What is the potential impact if exploitation succeeds?
The reported CVSS vector indicates low confidentiality, integrity, and availability impact, with scope changed. Because this is XSS, successful exploitation may allow attacker-controlled script to run in the context of a user who interacts with the malicious content.
Which plugin versions are affected?
Newsletter plugin versions 9.3.3 and earlier are identified as affected. The provided data does not identify a fixed version.