CVE-2020-35933: Thenewsletterplugin Newsletter
Medium severity, CVSS 6.5. EPSS: 0.9% chance of exploitation in the next 30 days.
A Reflected Authenticated Cross-Site Scripting (XSS) vulnerability in the Newsletter plugin before 6.8.2 for WordPress allows remote attackers to trick a victim into submitting a tnpc_render AJAX request containing either JavaScript in an options parameter, or a base64-encoded JSON string containing JavaScript in the encoded_options parameter.
Affected products
- Thenewsletterplugin Newsletter: before 6.8.2 (fixed in 6.8.2)
Published 2021-01-01. Last modified 2026-06-17.