WP Clinic
Entrar Registrarse

SEGURIDAD DE PLUGINS

¿Es seguro Newsletter?

Vulnerabilidades conocidas, compatibilidad con PHP y alternativas más seguras para el plugin de WordPress Newsletter — verificado contra la base de datos de seguridad local de WP Clinic.

Qué hace este plugin

  • Slug: newsletter
  • 200000+ instalaciones activas

Email Marketingnewslettersignup formssubscriptionwelcome email

Estado de mantenimiento

  • Última versión conocida: 9.3.1
  • Requiere PHP: 7.0+
  • PHP máximo soportado (analizado): 8.4

Vulnerabilidades conocidas

12 CVEs conocidos registrados para Newsletter.

CVE Vulnerabilidad Tipo Gravedad Afectadas Corregido en Publicado Estado
CVE-2025-67999 Newsletter – Send awesome emails from WordPress [newsletter] < 9.1.0 Neutralización incorrecta de elementos especiales en un comando SQL (inyección SQL) Alta 7,6 < 9.1.0 9.1.0 2025-12-15 ✓ corregido en la última versión
CVE-2024-5317 Newsletter – Send awesome emails from WordPress [newsletter] < 8.3.5 Neutralización incorrecta de la entrada al generar la página web (Cross-site Scripting / XSS) Media 6,1 < 8.3.5 8.3.5 2024-06-04 ✓ corregido en la última versión
CVE-2024-31434 Newsletter – Send awesome emails from WordPress [newsletter] < 8.0.7 Falsificación de petición en sitios cruzados (CSRF) Media 5,4 < 8.0.7 8.0.7 2024-04-10 ✓ corregido en la última versión
CVE-2024-30522 Newsletter – Send awesome emails from WordPress [newsletter] < 8.2.1 Elusión de autenticación mediante suplantación (spoofing) Media 5,3 < 8.2.1 8.2.1 2024-03-28 ✓ corregido en la última versión
Newsletter – Send awesome emails from WordPress [newsletter] < 8.0.7 Desconocido < 8.0.7 8.0.7 2024-01-10 ✓ corregido en la última versión
CVE-2023-4772 Newsletter – Send awesome emails from WordPress [newsletter] < 7.9.0 Neutralización incorrecta de la entrada al generar la página web (Cross-site Scripting / XSS) Media 5,4 < 7.9.0 7.9.0 2023-08-17 ✓ corregido en la última versión
CVE-2023-27922 Newsletter – Send awesome emails from WordPress [newsletter] < 7.6.9 Neutralización incorrecta de la entrada al generar la página web (Cross-site Scripting / XSS) Media 6,1 < 7.6.9 7.6.9 2023-05-09 ✓ corregido en la última versión
Newsletter – Send awesome emails from WordPress [newsletter] < 7.6.9 Desconocido < 7.6.9 7.6.9 2023-03-29 ✓ corregido en la última versión

CVE-2025-67999

The Newsletter plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 9.0.9 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with administrator-level access and above, to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: Wordfence

CVE-2024-5317

The Newsletter plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'np1' parameter in all versions up to, and including, 8.3.4 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: CVE.org

CVE-2024-31434

Update the WordPress Newsletter plugin to the latest available version (at least 8.0.7). Dhabaleshwar Das discovered and reported this Cross Site Request Forgery (CSRF) vulnerability in WordPress Newsletter Plugin. This could allow a malicious actor to force higher privileged users to execute unwanted actions under their current authentication. This vulnerability has been fixed in version 8.0.7. This vulnerability was reported to and published by Patchstack. Our users receive alerts and protections up to 48 hours in advance. Have additional information or questions about this entry? Get in touch.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: Patchstack

CVE-2024-30522

Update the WordPress Newsletter plugin to the latest available version (at least 8.2.1). Mika discovered and reported this Bypass Vulnerability vulnerability in WordPress Newsletter Plugin. A bypass vulnerability could allow a malicious actor to bypass certain restrictions in the code. This vulnerability has been fixed in version 8.2.1. This vulnerability was reported to and published by Patchstack. Our users receive alerts and protections up to 48 hours in advance. Have additional information or questions about this entry? Get in touch.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: Patchstack

Newsletter – Send awesome emails from WordPress [newsletter] < 8.0.7

The Newsletter – Send awesome emails from WordPress plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 8.0.6. This is due to missing or incorrect nonce validation in the main/welcome.php file. This makes it possible for unauthenticated attackers to modify the plugin's settings and send test emails via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: Wordfence

CVE-2023-4772

Update the WordPress Email Newsletter plugin to the latest available version (at least 7.9.0). Lana Codes discovered and reported this Cross Site Scripting (XSS) vulnerability in WordPress Email Newsletter Plugin. This could allow a malicious actor to inject malicious scripts, such as redirects, advertisements, and other HTML payloads into your website which will be executed when guests visit your site. This vulnerability has been fixed in version 7.9.0.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: Patchstack

CVE-2023-27922

WordPress Plugin "Newsletter" provided by Stefano Lissa & The Newsletter Team contains a cross-site scripting vulnerability (CWE-79). Gen Sato of Mitsui Bussan Secure Directions, Inc. reported this vulnerability to the developer and coordinated. JPCERT/CC published respective advisories in order to notify users of this vulnerability.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: jvndb.jvn.jp

Newsletter – Send awesome emails from WordPress [newsletter] < 7.6.9

Update the WordPress Email Newsletter plugin to the latest available version (at least 7.6.9). Unknown discovered and reported this Cross Site Scripting (XSS) vulnerability in WordPress Newsletter Plugin. This could allow a malicious actor to inject malicious scripts, such as redirects, advertisements, and other HTML payloads into your website which will be executed when guests visit your site. This vulnerability has been fixed in version 7.6.9.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: Patchstack

+ 25 vulnerabilidades conocidas más
CVE Vulnerabilidad Tipo Gravedad Afectadas Corregido en Publicado Estado
Newsletter – Send awesome emails from WordPress [newsletter] < 7.6.9 Desconocido < 7.6.9 7.6.9 2023-03-27 ✓ corregido en la última versión
CVE-2022-1889 Newsletter – Send awesome emails from WordPress [newsletter] < 7.4.6 Neutralización incorrecta de la entrada al generar la página web (Cross-site Scripting / XSS) Media 4,8 < 7.4.6 7.4.6 2022-05-30 ✓ corregido en la última versión
CVE-2022-1756 Newsletter – Send awesome emails from WordPress [newsletter] < 7.4.5 Neutralización incorrecta de la entrada al generar la página web (Cross-site Scripting / XSS) Media 6,1 < 7.4.5 7.4.5 2022-05-23 ✓ corregido en la última versión
Newsletter – Send awesome emails from WordPress [newsletter] < 7.4.5 Desconocido < 7.4.5 7.4.5 2022-05-17 ✓ corregido en la última versión
Newsletter – Send awesome emails from WordPress [newsletter] < 6.5.4 Desconocido < 6.5.4 6.5.4 2021-03-16 ✓ corregido en la última versión
CVE-2020-35933 Newsletter – Send awesome emails from WordPress [newsletter] < 6.8.2 Neutralización incorrecta de la entrada al generar la página web (Cross-site Scripting / XSS) Media 6,5 < 6.8.2 6.8.2 2020-08-03 ✓ corregido en la última versión
CVE-2020-35932 Newsletter – Send awesome emails from WordPress [newsletter] < 6.8.2 Deserialización de datos no confiables Alta 8,8 < 6.8.2 6.8.2 2020-08-02 ✓ corregido en la última versión
Newsletter – Send awesome emails from WordPress [newsletter] < 6.7.7 Desconocido < 6.7.7 6.7.7 2020-07-12 ✓ corregido en la última versión
Newsletter – Send awesome emails from WordPress [newsletter] < 6.7.7 Desconocido < 6.7.7 6.7.7 2020-07-12 ✓ corregido en la última versión
Newsletter – Send awesome emails from WordPress [newsletter] < 6.5.4 Desconocido < 6.5.4 6.5.4 2020-03-16 ✓ corregido en la última versión
Newsletter – Send awesome emails from WordPress [newsletter] < 3.0.9 Desconocido < 3.0.9 3.0.9 2015-10-18 ✓ corregido en la última versión
Newsletter – Send awesome emails from WordPress [newsletter] < 3.2.7 Desconocido < 3.2.7 3.2.7 2015-05-15 ✓ corregido en la última versión
Newsletter – Send awesome emails from WordPress [newsletter] < 3.8.3 Desconocido < 3.8.3 3.8.3 2015-03-30 ✓ corregido en la última versión
Newsletter – Send awesome emails from WordPress [newsletter] < 3.8.3 Desconocido < 3.8.3 3.8.3 2015-03-30 ✓ corregido en la última versión
Newsletter – Send awesome emails from WordPress [newsletter] < 3.2.7 Desconocido < 3.2.7 3.2.7 2013-05-14 ✓ corregido en la última versión
Newsletter – Send awesome emails from WordPress [newsletter] < 8.7.1 Neutralización incorrecta de la entrada al generar la página web (Cross-site Scripting / XSS) Media 4,8 < 8.7.1 8.7.1 0000-00-00 ✓ corregido en la última versión
CVE-2025-3584 Newsletter – Send awesome emails from WordPress [newsletter] < 8.8.2 Neutralización incorrecta de la entrada al generar la página web (Cross-site Scripting / XSS) Media 4,8 < 8.8.2 8.8.2 0000-00-00 ✓ corregido en la última versión
CVE-2026-1051 Newsletter – Send awesome emails from WordPress [newsletter] < 9.1.1 Desconocido < 9.1.1 9.1.1 0000-00-00 ✓ corregido en la última versión
Newsletter – Send awesome emails from WordPress [newsletter] < 8.8.5 Media 4,8 < 8.8.5 8.8.5 0000-00-00 ✓ corregido en la última versión
Newsletter – Send awesome emails from WordPress [newsletter] < 8.8.5 Media 4,8 < 8.8.5 8.8.5 0000-00-00 ✓ corregido en la última versión
Newsletter – Send awesome emails from WordPress [newsletter] < 6.7.7 Desconocido < 6.7.7 6.7.7 ✓ corregido en la última versión
Newsletter – Send awesome emails from WordPress [newsletter] < 6.5.4 Desconocido < 6.5.4 6.5.4 ✓ corregido en la última versión
Newsletter – Send awesome emails from WordPress [newsletter] < 3.8.3 Desconocido < 3.8.3 3.8.3 ✓ corregido en la última versión
Newsletter – Send awesome emails from WordPress [newsletter] < 3.2.7 Desconocido < 3.2.7 3.2.7 ✓ corregido en la última versión
Newsletter – Send awesome emails from WordPress [newsletter] < 3.0.9 Desconocido < 3.0.9 3.0.9 ✓ corregido en la última versión

Newsletter – Send awesome emails from WordPress [newsletter] < 7.6.9

The Newsletter plugin for WordPress may be vulnerable to Reflected Cross-Site Scripting via the $_SERVER['REQUEST_URI'] parameter in versions up to, and including, 7.6.8 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a victim into performing an action such as clicking on a link. Only victims using older browser should be impacted as newer browsers urlencode the REQUEST_URI parameter by default

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: Wordfence

CVE-2022-1889

The Newsletter plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the preheader_text value in versions up to, and including, 7.4.5 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers with administrative level permissions and above to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This only affects multi-site installations and installations where unfiltered_html has been disabled.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: Wordfence

CVE-2022-1756

The Newsletter WordPress plugin before 7.4.5 does not sanitize and escape the $_SERVER['REQUEST_URI'] before echoing it back in admin pages. Although this uses addslashes, and most modern browsers automatically URLEncode requests, this is still vulnerable to Reflected XSS in older browsers such as Internet Explorer 9 or below.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: CVE.org

Newsletter – Send awesome emails from WordPress [newsletter] < 7.4.5

Reflected Cross-Site Scripting (XSS) vulnerability discovered in WordPress Newsletter plugin (versions <= 7.4.4). Update the WordPress Newsletter plugin to the latest available version (at least 7.4.5).

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: Patchstack

Newsletter – Send awesome emails from WordPress [newsletter] < 6.5.4

CSV Injection vulnerability discovered by Fortinet in WordPress Newsletter plugin (versions <= 6.5.3).

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: Patchstack

CVE-2020-35933

Newsletter suffers from an Authenticated Reflected Cross-Site Scripting(XSS) vulnerability via the ‘tnpc_render’ AJAX action found in newsletter/emails/emails.php. Due to how the corresponding ‘tnpc_render_callback‘ function decodes input via the ‘restore_options_from_request’ function and renders them via the ‘render_block’ function, it is possible to use this function to render arbitrary JavaScript in several ways when sending a POST request to wp-admin/admin-ajax.php with the ‘action’ POST parameter set to ‘tnpc_render’: In an array element of the ‘options’ parameter - for example, by sending a request with the ‘b’ parameter set to ‘html’, and the ‘options[html]’ parameter set to arbitrary JavaScript In the ‘encoded_options’ parameter - for example by sending a request with the ‘b’ parameter set to ‘html’, the ‘options’ parameter set an empty array (e.g. options[]=&) and the ‘encoded_options’ parameter set to a base64-encoded JSON string containing the arbitrary JavaScript in the ‘html’ element.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: WPScan

CVE-2020-35932

The ‘restore_options_from_request‘ function called by the AJAX function ‘tnpc_render_callback‘ runs ‘unserialize’ directly on ‘$options['inline_edits']’ which is provided by user input in the $_POST[‘options’] parameter. This creates the potential for an Object Injection vulnerability. For example, a user with minimal permissions, such as a subscriber, could send a POST request to wp-admin/admin-ajax.php with the ‘action’ parameter set to ‘tpnc_render’ and the ‘options[inline_edits]’ parameter set to a serialized object. Although the Newsletter plugin does not itself use any magic methods such as __destruct or __wakeup which could be used to complete a POP chain, these methods are common in 3rd party libraries and other plugins, and as such could be used as part of a POP chain which could be used to execute arbitrary code or have other critical-severity impacts.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: WPScan

Newsletter – Send awesome emails from WordPress [newsletter] < 6.7.7

Authenticated Stored Cross-Site Scripting (XSS) vulnerability discovered by Chevon Phillip in WordPress Newsletter plugin (versions <= 6.7.6).

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: Patchstack

Newsletter – Send awesome emails from WordPress [newsletter] < 6.7.7

The Newsletter plugin for WordPress is vulnerable to Stored Cross-Site Scripting via multiple parameters in versions up to, and including, 6.7.6 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: Wordfence

Newsletter – Send awesome emails from WordPress [newsletter] < 6.5.4

The Newsletter plugin for WordPress is vulnerable to CSV Injection in versions up to, and including, 6.5.3 by the use of Microsoft Excel DDE function, or to leak data via maliciously injected hyperlinks. This allows non-privileged attackers to embed untrusted input into exported CSV files, which can result in code execution when these files are downloaded and opened on a local system with a vulnerable configuration.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: Wordfence

Newsletter – Send awesome emails from WordPress [newsletter] < 3.0.9

Because of this vulnerability, remote authenticated users can execute arbitrary SQL commands. Upgrade the plugin.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: Patchstack

Newsletter – Send awesome emails from WordPress [newsletter] < 3.2.7

Because of this vulnerability, the attackers can inject arbitrary JavaScript or HTML code. Update the plugin.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: Patchstack

Newsletter – Send awesome emails from WordPress [newsletter] < 3.8.3

This plugin is prone to an open redirection vulnerability. Update the plugin.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: Patchstack

Newsletter – Send awesome emails from WordPress [newsletter] < 3.8.3

The Newsletter plugin is susceptible to an Open Redirect vulnerability. This issue is due to the fact user input it taken, and trusted, without validation. This user input is used when tracking link clicks, via the ‘newsletter/statistics/link.php’ script. User input is Base64 encoded, and split on the ‘;’ character, the third column of which can be manipulated in order to control where the user is redirected to.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: Wordfence

Newsletter – Send awesome emails from WordPress [newsletter] < 3.2.7

The Newsletter plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘alert’ parameter in the 'page.php' file in versions up to, and including, 3.2.6 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: Wordfence

Newsletter – Send awesome emails from WordPress [newsletter] < 8.7.1

The Newsletter plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the preheader_text value in versions up to, and including, 8.7.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers with administrative level permissions and above to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This only affects multi-site installations and installations where unfiltered_html has been disabled.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: Wordfence

CVE-2025-3584

The Newsletter – Send awesome emails from WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 8.8.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level permissions and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This only affects multi-site installations and installations where unfiltered_html has been disabled.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: Wordfence

CVE-2026-1051

The Newsletter – Send awesome emails from WordPress plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 9.1.0. This is due to missing or incorrect nonce validation on the hook_newsletter_action() function. This makes it possible for unauthenticated attackers to unsubscribe newsletter subscribers via a forged request granted they can trick a logged-in user into performing an action such as clicking on a link.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: Wordfence

Newsletter – Send awesome emails from WordPress [newsletter] < 8.8.5

The Newsletter – Send awesome emails from WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 8.8.4 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level permissions and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This only affects multi-site installations and installations where unfiltered_html has been disabled.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: Wordfence

Newsletter – Send awesome emails from WordPress [newsletter] < 8.8.5

The Newsletter – Send awesome emails from WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 8.8.4 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level permissions and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This only affects multi-site installations and installations where unfiltered_html has been disabled.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: Wordfence

Newsletter – Send awesome emails from WordPress [newsletter] < 6.7.7

An Authenticated Stored Cross-Site Scripting (XSS) was discovered within the Company Info "Motto" field. When creating a new newsletter using an empty template with the header module, the XSS would execute. This was later fixed in version: 6.7.7

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: WPScan

Newsletter – Send awesome emails from WordPress [newsletter] < 6.5.4

A CSV Injection vulnerability was discovered in Wordpress Newsletter plugin. It allows a user with low level privileges or no privileges to inject a command in subscription form that will be included in the exported CSV file, leading to possible code execution.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: WPScan

Newsletter – Send awesome emails from WordPress [newsletter] < 3.8.3

The Newsletter plugin is susceptible to an Open Redirect vulnerability. This issue is due to the fact user input it taken, and trusted, without validation. This user input is used when tracking link clicks, via the ‘newsletter/statistics/link.php’ script. User input is Base64 encoded, and split on the ‘;’ character, the third column of which can be manipulated in order to control where the user is redirected to.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: WPScan

Newsletter – Send awesome emails from WordPress [newsletter] < 3.2.7

The Newsletter WordPress plugin was affected by a Cross-Site Scripting (XSS) security vulnerability.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: WPScan

Newsletter – Send awesome emails from WordPress [newsletter] < 3.0.9

The Newsletter WordPress plugin was affected by a SQL Injection security vulnerability.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: WPScan

Cómo solucionarlo

Mantén Newsletter actualizado — 9.3.1 es la última versión en wordpress.org, y cada CVE de arriba indica la versión exacta que lo corrigió ("Corregido en").

Este es el historial completo de vulnerabilidades conocidas del plugin, no un escaneo de una instalación específica — ejecuta un escaneo gratis de tu propio sitio para verificar tu versión instalada exacta.

Alternativas más seguras / más establecidas

Verifica tu propio sitio WordPress

Ejecuta un escaneo pasivo gratis ahora, o crea una cuenta gratuita e instala el plugin de WP Clinic para un escaneo profundo de toda tu cuenta de hosting y reparación asistida por IA.