Known Vulnerabilities for Plugin Newsletter Plugin by Wordpress
Listed below are 1 of the newest known vulnerabilities associated with "Plugin Newsletter Plugin" by "Wordpress".
These CVEs are retrieved based on exact matches on listed software, hardware, and vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed software information are still displayed.
Data on known vulnerable versions is also displayed based on information from known CPEs
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2026-3614 json | The AcyMailing plugin for WordPress is vulnerable to privilege escalation in all versions From 9.11.0 up to, and including, 1... | Not Provided | 2026-04-16 | 2026-04-16 |
| CVE-2025-14852 json | The MDirector Newsletter plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and includin... | Not Provided | 2026-02-14 | 2026-04-08 |
| CVE-2025-3421 json | The Everest Forms – Contact Form, Quiz, Survey, Newsletter & Payment Form Builder for WordPress plugin for WordPress is vul... | Not Provided | 2025-04-11 | 2026-04-08 |
| CVE-2024-5674 json | The Newsletter - API v1 and v2 addon plugin for WordPress is vulnerable to unauthorized subscribers management due to PHP typ... | Not Provided | 2024-06-12 | 2026-04-08 |
| CVE-2024-5317 json | The Newsletter plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'np1' parameter in all versions up t... | Not Provided | 2024-06-05 | 2026-04-08 |
| CVE-2024-3961 json | The ConvertKit – Email Newsletter, Email Marketing, Subscribers and Landing Pages plugin for WordPress is vulnerable to una... | Not Provided | 2024-06-21 | 2026-04-08 |
| CVE-2024-2392 json | The Blocksy Companion plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Newsletter widget in... | Not Provided | 2024-03-22 | 2026-04-08 |
| CVE-2024-1793 json | The AWeber – Free Sign Up Form and Landing Page Builder Plugin for Lead Generation and Email Newsletter Growth plugin for W... | Not Provided | 2024-03-13 | 2026-04-08 |
| CVE-2023-47757 json | Missing Authorization, Cross-Site Request Forgery (CSRF) vulnerability in AWeber AWeber – Free Sign Up Form and Landing Pag... | Not Provided | 2023-11-17 | 2026-04-28 |
| CVE-2023-4772 json | The Newsletter plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'newsletter_form' shortcode in versi... | Not Provided | 2023-09-07 | 2026-04-08 |
Known Affected Configurations (CPE V2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Wordpress | Plugin Newsletter Plugin | 1.5 |