+ 25 vulnerabilidades conocidas más
| CVE |
Vulnerabilidad |
Tipo |
Gravedad |
Afectadas |
Corregido en |
Publicado |
Estado |
|
—
|
Newsletter – Send awesome emails from WordPress [newsletter] < 7.6.9 |
— |
Desconocido
|
< 7.6.9
|
7.6.9 |
2023-03-27 |
✓ corregido en la última versión
|
|
CVE-2022-1889
|
Newsletter – Send awesome emails from WordPress [newsletter] < 7.4.6 |
Neutralización incorrecta de la entrada al generar la página web (Cross-site Scripting / XSS) |
Media
4,8
|
< 7.4.6
|
7.4.6 |
2022-05-30 |
✓ corregido en la última versión
|
|
CVE-2022-1756
|
Newsletter – Send awesome emails from WordPress [newsletter] < 7.4.5 |
Neutralización incorrecta de la entrada al generar la página web (Cross-site Scripting / XSS) |
Media
6,1
|
< 7.4.5
|
7.4.5 |
2022-05-23 |
✓ corregido en la última versión
|
|
—
|
Newsletter – Send awesome emails from WordPress [newsletter] < 7.4.5 |
— |
Desconocido
|
< 7.4.5
|
7.4.5 |
2022-05-17 |
✓ corregido en la última versión
|
|
—
|
Newsletter – Send awesome emails from WordPress [newsletter] < 6.5.4 |
— |
Desconocido
|
< 6.5.4
|
6.5.4 |
2021-03-16 |
✓ corregido en la última versión
|
|
CVE-2020-35933
|
Newsletter – Send awesome emails from WordPress [newsletter] < 6.8.2 |
Neutralización incorrecta de la entrada al generar la página web (Cross-site Scripting / XSS) |
Media
6,5
|
< 6.8.2
|
6.8.2 |
2020-08-03 |
✓ corregido en la última versión
|
|
CVE-2020-35932
|
Newsletter – Send awesome emails from WordPress [newsletter] < 6.8.2 |
Deserialización de datos no confiables |
Alta
8,8
|
< 6.8.2
|
6.8.2 |
2020-08-02 |
✓ corregido en la última versión
|
|
—
|
Newsletter – Send awesome emails from WordPress [newsletter] < 6.7.7 |
— |
Desconocido
|
< 6.7.7
|
6.7.7 |
2020-07-12 |
✓ corregido en la última versión
|
|
—
|
Newsletter – Send awesome emails from WordPress [newsletter] < 6.7.7 |
— |
Desconocido
|
< 6.7.7
|
6.7.7 |
2020-07-12 |
✓ corregido en la última versión
|
|
—
|
Newsletter – Send awesome emails from WordPress [newsletter] < 6.5.4 |
— |
Desconocido
|
< 6.5.4
|
6.5.4 |
2020-03-16 |
✓ corregido en la última versión
|
|
—
|
Newsletter – Send awesome emails from WordPress [newsletter] < 3.0.9 |
— |
Desconocido
|
< 3.0.9
|
3.0.9 |
2015-10-18 |
✓ corregido en la última versión
|
|
—
|
Newsletter – Send awesome emails from WordPress [newsletter] < 3.2.7 |
— |
Desconocido
|
< 3.2.7
|
3.2.7 |
2015-05-15 |
✓ corregido en la última versión
|
|
—
|
Newsletter – Send awesome emails from WordPress [newsletter] < 3.8.3 |
— |
Desconocido
|
< 3.8.3
|
3.8.3 |
2015-03-30 |
✓ corregido en la última versión
|
|
—
|
Newsletter – Send awesome emails from WordPress [newsletter] < 3.8.3 |
— |
Desconocido
|
< 3.8.3
|
3.8.3 |
2015-03-30 |
✓ corregido en la última versión
|
|
—
|
Newsletter – Send awesome emails from WordPress [newsletter] < 3.2.7 |
— |
Desconocido
|
< 3.2.7
|
3.2.7 |
2013-05-14 |
✓ corregido en la última versión
|
|
—
|
Newsletter – Send awesome emails from WordPress [newsletter] < 8.7.1 |
Neutralización incorrecta de la entrada al generar la página web (Cross-site Scripting / XSS) |
Media
4,8
|
< 8.7.1
|
8.7.1 |
0000-00-00 |
✓ corregido en la última versión
|
|
CVE-2025-3584
|
Newsletter – Send awesome emails from WordPress [newsletter] < 8.8.2 |
Neutralización incorrecta de la entrada al generar la página web (Cross-site Scripting / XSS) |
Media
4,8
|
< 8.8.2
|
8.8.2 |
0000-00-00 |
✓ corregido en la última versión
|
|
CVE-2026-1051
|
Newsletter – Send awesome emails from WordPress [newsletter] < 9.1.1 |
— |
Desconocido
|
< 9.1.1
|
9.1.1 |
0000-00-00 |
✓ corregido en la última versión
|
|
—
|
Newsletter – Send awesome emails from WordPress [newsletter] < 8.8.5 |
— |
Media
4,8
|
< 8.8.5
|
8.8.5 |
0000-00-00 |
✓ corregido en la última versión
|
|
—
|
Newsletter – Send awesome emails from WordPress [newsletter] < 8.8.5 |
— |
Media
4,8
|
< 8.8.5
|
8.8.5 |
0000-00-00 |
✓ corregido en la última versión
|
|
—
|
Newsletter – Send awesome emails from WordPress [newsletter] < 6.7.7 |
— |
Desconocido
|
< 6.7.7
|
6.7.7 |
— |
✓ corregido en la última versión
|
|
—
|
Newsletter – Send awesome emails from WordPress [newsletter] < 6.5.4 |
— |
Desconocido
|
< 6.5.4
|
6.5.4 |
— |
✓ corregido en la última versión
|
|
—
|
Newsletter – Send awesome emails from WordPress [newsletter] < 3.8.3 |
— |
Desconocido
|
< 3.8.3
|
3.8.3 |
— |
✓ corregido en la última versión
|
|
—
|
Newsletter – Send awesome emails from WordPress [newsletter] < 3.2.7 |
— |
Desconocido
|
< 3.2.7
|
3.2.7 |
— |
✓ corregido en la última versión
|
|
—
|
Newsletter – Send awesome emails from WordPress [newsletter] < 3.0.9 |
— |
Desconocido
|
< 3.0.9
|
3.0.9 |
— |
✓ corregido en la última versión
|
Newsletter – Send awesome emails from WordPress [newsletter] < 7.6.9
The Newsletter plugin for WordPress may be vulnerable to Reflected Cross-Site Scripting via the $_SERVER['REQUEST_URI'] parameter in versions up to, and including, 7.6.8 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a victim into performing an action such as clicking on a link. Only victims using older browser should be impacted as newer browsers urlencode the REQUEST_URI parameter by default
Descripción técnica mostrada en el idioma original de la fuente (inglés).
Fuente:
Wordfence
CVE-2022-1889
The Newsletter plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the preheader_text value in versions up to, and including, 7.4.5 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers with administrative level permissions and above to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This only affects multi-site installations and installations where unfiltered_html has been disabled.
Descripción técnica mostrada en el idioma original de la fuente (inglés).
Fuente:
Wordfence
CVE-2022-1756
The Newsletter WordPress plugin before 7.4.5 does not sanitize and escape the $_SERVER['REQUEST_URI'] before echoing it back in admin pages. Although this uses addslashes, and most modern browsers automatically URLEncode requests, this is still vulnerable to Reflected XSS in older browsers such as Internet Explorer 9 or below.
Descripción técnica mostrada en el idioma original de la fuente (inglés).
Fuente:
CVE.org
Newsletter – Send awesome emails from WordPress [newsletter] < 7.4.5
Reflected Cross-Site Scripting (XSS) vulnerability discovered in WordPress Newsletter plugin (versions <= 7.4.4).
Update the WordPress Newsletter plugin to the latest available version (at least 7.4.5).
Descripción técnica mostrada en el idioma original de la fuente (inglés).
Fuente:
Patchstack
Newsletter – Send awesome emails from WordPress [newsletter] < 6.5.4
CSV Injection vulnerability discovered by Fortinet in WordPress Newsletter plugin (versions <= 6.5.3).
Descripción técnica mostrada en el idioma original de la fuente (inglés).
Fuente:
Patchstack
CVE-2020-35933
Newsletter suffers from an Authenticated Reflected Cross-Site Scripting(XSS) vulnerability via the ‘tnpc_render’ AJAX action found in newsletter/emails/emails.php. Due to how the corresponding ‘tnpc_render_callback‘ function decodes input via the ‘restore_options_from_request’ function and renders them via the ‘render_block’ function, it is possible to use this function to render arbitrary JavaScript in several ways when sending a POST request to wp-admin/admin-ajax.php with the ‘action’ POST parameter set to ‘tnpc_render’:
In an array element of the ‘options’ parameter - for example, by sending a request with the ‘b’ parameter set to ‘html’, and the ‘options[html]’ parameter set to arbitrary JavaScript
In the ‘encoded_options’ parameter - for example by sending a request with the ‘b’ parameter set to ‘html’, the ‘options’ parameter set an empty array (e.g. options[]=&) and the ‘encoded_options’ parameter set to a base64-encoded JSON string containing the arbitrary JavaScript in the ‘html’ element.
Descripción técnica mostrada en el idioma original de la fuente (inglés).
Fuente:
WPScan
CVE-2020-35932
The ‘restore_options_from_request‘ function called by the AJAX function ‘tnpc_render_callback‘ runs ‘unserialize’ directly on ‘$options['inline_edits']’ which is provided by user input in the $_POST[‘options’] parameter. This creates the potential for an Object Injection vulnerability. For example, a user with minimal permissions, such as a subscriber, could send a POST request to wp-admin/admin-ajax.php with the ‘action’ parameter set to ‘tpnc_render’ and the ‘options[inline_edits]’ parameter set to a serialized object.
Although the Newsletter plugin does not itself use any magic methods such as __destruct or __wakeup which could be used to complete a POP chain, these methods are common in 3rd party libraries and other plugins, and as such could be used as part of a POP chain which could be used to execute arbitrary code or have other critical-severity impacts.
Descripción técnica mostrada en el idioma original de la fuente (inglés).
Fuente:
WPScan
Newsletter – Send awesome emails from WordPress [newsletter] < 6.7.7
Authenticated Stored Cross-Site Scripting (XSS) vulnerability discovered by Chevon Phillip in WordPress Newsletter plugin (versions <= 6.7.6).
Descripción técnica mostrada en el idioma original de la fuente (inglés).
Fuente:
Patchstack
Newsletter – Send awesome emails from WordPress [newsletter] < 6.7.7
The Newsletter plugin for WordPress is vulnerable to Stored Cross-Site Scripting via multiple parameters in versions up to, and including, 6.7.6 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
Descripción técnica mostrada en el idioma original de la fuente (inglés).
Fuente:
Wordfence
Newsletter – Send awesome emails from WordPress [newsletter] < 6.5.4
The Newsletter plugin for WordPress is vulnerable to CSV Injection in versions up to, and including, 6.5.3 by the use of Microsoft Excel DDE function, or to leak data via maliciously injected hyperlinks. This allows non-privileged attackers to embed untrusted input into exported CSV files, which can result in code execution when these files are downloaded and opened on a local system with a vulnerable configuration.
Descripción técnica mostrada en el idioma original de la fuente (inglés).
Fuente:
Wordfence
Newsletter – Send awesome emails from WordPress [newsletter] < 3.0.9
Because of this vulnerability, remote authenticated users can execute arbitrary SQL commands.
Upgrade the plugin.
Descripción técnica mostrada en el idioma original de la fuente (inglés).
Fuente:
Patchstack
Newsletter – Send awesome emails from WordPress [newsletter] < 3.2.7
Because of this vulnerability, the attackers can inject arbitrary JavaScript or HTML code.
Update the plugin.
Descripción técnica mostrada en el idioma original de la fuente (inglés).
Fuente:
Patchstack
Newsletter – Send awesome emails from WordPress [newsletter] < 3.8.3
This plugin is prone to an open redirection vulnerability.
Update the plugin.
Descripción técnica mostrada en el idioma original de la fuente (inglés).
Fuente:
Patchstack
Newsletter – Send awesome emails from WordPress [newsletter] < 3.8.3
The Newsletter plugin is susceptible to an Open Redirect vulnerability. This issue is due to the fact user input it taken, and trusted, without validation. This user input is used when tracking link clicks, via the ‘newsletter/statistics/link.php’ script. User input is Base64 encoded, and split on the ‘;’ character, the third column of which can be manipulated in order to control where the user is redirected to.
Descripción técnica mostrada en el idioma original de la fuente (inglés).
Fuente:
Wordfence
Newsletter – Send awesome emails from WordPress [newsletter] < 3.2.7
The Newsletter plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘alert’ parameter in the 'page.php' file in versions up to, and including, 3.2.6 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.
Descripción técnica mostrada en el idioma original de la fuente (inglés).
Fuente:
Wordfence
Newsletter – Send awesome emails from WordPress [newsletter] < 8.7.1
The Newsletter plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the preheader_text value in versions up to, and including, 8.7.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers with administrative level permissions and above to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This only affects multi-site installations and installations where unfiltered_html has been disabled.
Descripción técnica mostrada en el idioma original de la fuente (inglés).
Fuente:
Wordfence
CVE-2025-3584
The Newsletter – Send awesome emails from WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 8.8.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level permissions and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This only affects multi-site installations and installations where unfiltered_html has been disabled.
Descripción técnica mostrada en el idioma original de la fuente (inglés).
Fuente:
Wordfence
CVE-2026-1051
The Newsletter – Send awesome emails from WordPress plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 9.1.0. This is due to missing or incorrect nonce validation on the hook_newsletter_action() function. This makes it possible for unauthenticated attackers to unsubscribe newsletter subscribers via a forged request granted they can trick a logged-in user into performing an action such as clicking on a link.
Descripción técnica mostrada en el idioma original de la fuente (inglés).
Fuente:
Wordfence
Newsletter – Send awesome emails from WordPress [newsletter] < 8.8.5
The Newsletter – Send awesome emails from WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 8.8.4 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level permissions and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This only affects multi-site installations and installations where unfiltered_html has been disabled.
Descripción técnica mostrada en el idioma original de la fuente (inglés).
Fuente:
Wordfence
Newsletter – Send awesome emails from WordPress [newsletter] < 8.8.5
The Newsletter – Send awesome emails from WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 8.8.4 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level permissions and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This only affects multi-site installations and installations where unfiltered_html has been disabled.
Descripción técnica mostrada en el idioma original de la fuente (inglés).
Fuente:
Wordfence
Newsletter – Send awesome emails from WordPress [newsletter] < 6.7.7
An Authenticated Stored Cross-Site Scripting (XSS) was discovered within the Company Info "Motto" field. When creating a new newsletter using an empty template with the header module, the XSS would execute.
This was later fixed in version: 6.7.7
Descripción técnica mostrada en el idioma original de la fuente (inglés).
Fuente:
WPScan
Newsletter – Send awesome emails from WordPress [newsletter] < 6.5.4
A CSV Injection vulnerability was discovered in Wordpress Newsletter plugin. It allows a user with low level privileges or no privileges to inject a command in subscription form that will be included in the exported CSV file, leading to possible code execution.
Descripción técnica mostrada en el idioma original de la fuente (inglés).
Fuente:
WPScan
Newsletter – Send awesome emails from WordPress [newsletter] < 3.8.3
The Newsletter plugin is susceptible to an Open Redirect vulnerability. This issue is due to the fact user input it taken, and trusted, without validation.
This user input is used when tracking link clicks, via the ‘newsletter/statistics/link.php’ script. User input is Base64 encoded, and split on the ‘;’ character, the third column of which can be manipulated in order to control where the user is redirected to.
Descripción técnica mostrada en el idioma original de la fuente (inglés).
Fuente:
WPScan
Newsletter – Send awesome emails from WordPress [newsletter] < 3.2.7
The Newsletter WordPress plugin was affected by a Cross-Site Scripting (XSS) security vulnerability.
Descripción técnica mostrada en el idioma original de la fuente (inglés).
Fuente:
WPScan
Newsletter – Send awesome emails from WordPress [newsletter] < 3.0.9
The Newsletter WordPress plugin was affected by a SQL Injection security vulnerability.
Descripción técnica mostrada en el idioma original de la fuente (inglés).
Fuente:
WPScan
Mantén Newsletter actualizado — 9.3.1 es la última versión en wordpress.org, y cada CVE de arriba indica la versión exacta que lo corrigió ("Corregido en").
Este es el historial completo de vulnerabilidades conocidas del plugin, no un escaneo de una instalación específica — ejecuta un escaneo gratis de tu propio sitio para verificar tu versión instalada exacta.