CVE-2020-35933: Thenewsletterplugin Newsletter

Medium severity, CVSS 6.5. EPSS: 0.9% chance of exploitation in the next 30 days.

A Reflected Authenticated Cross-Site Scripting (XSS) vulnerability in the Newsletter plugin before 6.8.2 for WordPress allows remote attackers to trick a victim into submitting a tnpc_render AJAX request containing either JavaScript in an options parameter, or a base64-encoded JSON string containing JavaScript in the encoded_options parameter.

Affected products

Published 2021-01-01. Last modified 2026-06-17.