Newsletters
newsletters-lite · plugin
Known security vulnerabilities for Newsletters. Find out in seconds which version runs on your site with WP Lens.
31 known vulnerabilities
3 critical · 18 exploitable without logging in · 2 with public exploit code · latest Sep 17, 2026
Listed on wordpress.org · latest 4.18.1 · last updated Sep 15, 2026 · 2K+ installs
wordpress.org status checked on Oct 2, 2026
Vulnerabilities
- Critical 9.8
CVE-2025-67911unauthenticated≤ 4.11
WordPress Newsletters plugin <= 4.11 - PHP Object Injection vulnerability
- Critical 9.8
CVE-2018-20987unauthenticated
The newsletters-lite plugin before 4.6.8.6 for WordPress has PHP object injection.
- Critical 9.1
CVE-2024-32954high privilege≤ 4.9.5
WordPress Newsletters plugin <= 4.9.5 - Arbitrary File Upload vulnerability
- High 8.8
CVE-2024-37227unauthenticated · needs a click≤ 4.9.7
WordPress Newsletters plugin <= 4.9.7 - Cross Site Request Forgery (CSRF) vulnerability
- High 8.8
CVE-2023-30478unauthenticated · needs a click≤ 4.8.8
WordPress Newsletters Plugin <= 4.8.8 is vulnerable to Cross Site Request Forgery (CSRF)
- High 8.8
CVE-2024-8247subscriber+≤ 4.9.9.2
Newsletters <= 4.9.9.2 - Authenticated Privilege Escalation
- High 8.8
CVE-2019-14788login required
wp-admin/admin-ajax.php?action=newsletters_exportmultiple in the Tribulant Newsletters plugin before 4.6.19 for WordPress allows directory t
- High 8.1
CVE-2026-57645unauthenticated · needs a click≤ 4.13
WordPress Newsletters plugin <= 4.13 - Broken Access Control vulnerability
- High 7.6
CVE-2026-66619admin≤ 4.18
WordPress Newsletters plugin <= 4.18 - SQL Injection vulnerability
- High 7.6
CVE-2025-30921high privilege≤ 4.9.9.7
WordPress Newsletters plugin <= 4.9.9.7 - SQL Injection vulnerability
- High 7.5
CVE-2026-3018unauthenticated≤ 4.13
Newsletters <= 4.13 - Unauthenticated SQL Injection via wpmlsubscriber_id Parameter
- High 7.5
CVE-2025-54034unauthenticated · needs a click≤ 4.10
WordPress Newsletters plugin <= 4.10 - Local File Inclusion vulnerability
- High 7.5
CVE-2024-32953unauthenticated≤ 4.9.5
WordPress Newsletters plugin <= 4.9.5 - Sensitive Data Exposure vulnerability
- High 7.3
CVE-2026-54840unauthenticated≤ 4.13
WordPress Newsletters plugin <= 4.13 - Broken Access Control vulnerability
- High 7.2
CVE-2025-2009unauthenticated≤ 4.9.9.7
Newsletters <= 4.9.9.7 - Unauthenticated Stored Cross-Site Scripting
- High 7.2
CVE-2025-4857admin≤ 4.9.9.9
Newsletters <= 4.9.9.9 - Authenticated (Administrator+) Local File Inclusion
- High 7.1
CVE-2026-57394unauthenticated · needs a click≤ 4.14
WordPress Newsletters plugin <= 4.14 - Cross Site Scripting (XSS) vulnerability
- High 7.1
CVE-2025-24599unauthenticated · needs a click≤ 4.9.9.6
WordPress Newsletters plugin <= 4.9.9.6 - Reflected Cross Site Scripting (XSS) vulnerability
- High 7.1
CVE-2024-47346unauthenticated · needs a click≤ 4.9.9.1
WordPress Newsletters plugin <= 4.9.9.1 - Reflected Cross Site Scripting (XSS) vulnerability
- High 7.1
CVE-2024-43279unauthenticated · needs a click≤ 4.9.8
WordPress Newsletters plugin <= 4.9.8 - Cross Site Scripting (XSS) vulnerability
- Medium 6.5
CVE-2025-69020login required≤ 4.12
WordPress Newsletters plugin <= 4.12 - Cross Site Scripting (XSS) vulnerability
- Medium 6.5
CVE-2025-3107contributor+≤ 4.9.9.8
Newsletters <= 4.9.9.8 - Authenticated (Contributor+) SQL Injection orderby Parameter
- Medium 6.4
CVE-2026-12939contributor+≤ 4.15
Newsletters <= 4.15 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'link' Shortcode Attribute
- Medium 6.4
CVE-2026-12938contributor+≤ 4.15
Newsletters <= 4.15 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'target' Shortcode Attribute
- Medium 6.4
CVE-2024-10181contributor+≤ 4.9.9.4
Newsletters <= 4.9.9.4 - Authenticated (Contributor+) Stored Cross-Site Scripting via newsletters_video Shortcode
- Medium 6.1
CVE-2024-13739unauthenticated · needs a click≤ 4.9.9.7
Newsletters <= 4.9.9.7 - Reflected Cross-Site Scripting via To Parameter
- Medium 6.1
CVE-2024-35718unauthenticated · needs a click≤ 4.9.5
WordPress Newsletters plugin <= 4.9.5 - Reflected Cross Site Scripting (XSS) vulnerability
- Medium 5.4
CVE-2019-14787login required
The Tribulant Newsletters plugin before 4.6.19 for WordPress allows XSS via the wp-admin/admin-ajax.php?action=newsletters_load_new_editor c
- Medium 5.3
CVE-2024-7411unauthenticated≤ 4.9.9
Newsletters <= 4.9.9 - Unauthenticated Full Path Disclosure
- Medium 4.3
CVE-2025-54035unauthenticated · needs a click≤ 4.10
WordPress Newsletters plugin <= 4.10 - Cross Site Request Forgery (CSRF) Vulnerability
- Medium 4.3
CVE-2026-75908author+≤ 4.17
Newsletters <= 4.17 - Missing Authorization to Authenticated (Author+) Arbitrary Modification via 'newsletters_mailinglistsroles' POST Parameter
The access label is read from the record's own text (e.g. “subscriber+”: subscriber and above). When the text names no role, CVSS decides between “login required” and “high privilege”; no role name is invented. “Needs a click”: the attack depends on a logged-in user following a link (CSRF, reflected XSS).