Newsletter

WordPress plugin · newsletter · WordPress.org ↗
0
Critical
0
High
2
Known total
0
Unfixed
Running Newsletter on your site? WP Alerts checks your installed version against every entry below and emails you only when one affects you. Free, no tracking.
Scan a site Monitor my sites →
SeverityVulnerabilityAffectedFixed inCVEPublished
MEDIUM
CVSS 4.8
Newsletter < 9.3.8 - Unauthenticated Subscriber PII Disclosure and Modification via Predictable Tracking Signature Key
CVE.org
>=0, <9.3.8 v9.3.8 CVE-2026-86824 Sep 17, 2026
MEDIUM
CVSS 5.3
Newsletter < 9.3.7 - Unauthenticated Open Redirect and Subscriber Token Disclosure via ncu Parameter
CVE.org
>=0, <9.3.7 v9.3.7 CVE-2026-86823 Sep 16, 2026

Data aggregated from WPVulnerability, NVD/NIST, ENISA EUVD, CVE.org and WordPress.org. Provided as-is; verify with the plugin author before acting. Disclaimer.