CVE · Medium

CVE-2023-27922 — Newsletter – Send awesome emails from WordPress [newsletter] < 7.6.9

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2023-27922 Newsletter – Send awesome emails from WordPress [newsletter] < 7.6.9 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Medium 6.1 < 7.6.9 7.6.9 2023-03-27

CVE-2023-27922

The Newsletter plugin for WordPress up to version 7.6.8 contains a reflected cross-site scripting vulnerability in the $_SERVER['REQUEST_URI'] parameter caused by inadequate sanitization and escaping of user input. An unauthenticated attacker could exploit this flaw by crafting a malicious link that injects arbitrary JavaScript code into a page, which would execute if a user clicks the link, though the vulnerability primarily affects users with older browsers since newer browsers automatically URL-encode the REQUEST_URI parameter.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.