
Newsletter – Send awesome emails from WordPress Security & Risk Analysis
wordpress.org/plugins/newsletterAn email marketing tool for your blog: subscription forms to create your lists with unlimited subscribers and newsletters.
Is Newsletter – Send awesome emails from WordPress Safe to Use in 2026?
Generally Safe
Score 89/100Newsletter – Send awesome emails from WordPress has a strong security track record. Known vulnerabilities have been patched promptly.
The 'newsletter' plugin v9.1.7 exhibits a mixed security posture. While it demonstrates good practices with a high percentage of SQL queries using prepared statements and properly escaped output, significant concerns arise from its attack surface and taint analysis results. Eleven of the fifteen AJAX handlers lack authentication checks, creating a substantial entry point for unauthorized actions. Furthermore, the presence of 5 high-severity taint flows indicates potential for malicious data to be processed without adequate sanitization, which could lead to vulnerabilities if not handled carefully. The plugin's vulnerability history, with 20 known CVEs including 2 high-severity issues, points to a pattern of past security weaknesses. While there are currently no unpatched CVEs, the variety of past vulnerability types (SQL Injection, XSS, CSRF, etc.) suggests a need for ongoing vigilance and robust security development processes. Overall, the plugin has strengths in its handling of SQL and output, but the exposure of AJAX endpoints and the high-severity taint flows represent immediate risks that require attention.
Key Concerns
- Unprotected AJAX handlers
- High severity taint flows
- History of 2 high-severity CVEs
- History of 18 medium-severity CVEs
- Bundled outdated library: TinyMCE v1.0
- Bundled outdated library: Select2
Newsletter – Send awesome emails from WordPress Security Vulnerabilities
CVEs by Year
Severity Breakdown
20 total CVEs
Newsletter – Send awesome emails from WordPress <= 9.1.0 - Cross-Site Request Forgery to Newsletter Unsubscription
Newsletter <= 9.0.9 - Authenticated (Administrator+) SQL Injection
Newsletter <= 8.8.4 - Authenticated (Administrator+) Stored Cross-Site Scripting
Newsletter <= 8.8.4 - Authenticated (Administrator+) Stored Cross-Site Scripting
Newsletter <= 8.8.1 - Authenticated (Admin+) Stored Cross-Site Scripting
Newsletter <= 8.7.0 - Authenticated (Admin+) Stored Cross-Site Scripting
Newsletter <= 8.3.4 - Unauthenticated Stored Cross-Site Scripting via np1
Newsletter <= 8.0.6 - Cross-Site Request Forgery
Newsletter <= 8.2.0 - IP Spoofing
Newsletter <= 8.0.6 - Cross-Site Request Forgery
Newsletter <= 7.8.9 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode
Newsletter <= 7.6.8 - Reflected Cross-Site Scripting
Newsletter <= 7.4.5 - Authenticated (Admin+) Stored Cross-Site Scripting
Newsletter – Send awesome emails from WordPress <= 7.4.4 - Reflected Cross-Site Scripting
Newsletter <= 6.8.1 - Reflected Cross-Site Scripting
Newsletter <= 6.8.1 - Authenticated PHP Object Injection
Newsletter <= 6.7.6 - Stored Cross-Site Scripting
Newsletter <= 6.5.3 - CSV Injection
Newsletter <= 3.8.2 - Open Redirect
Newsletter <= 3.2.6 - Reflected Cross-Site Scripting
Newsletter – Send awesome emails from WordPress Code Analysis
Bundled Libraries
SQL Query Safety
Output Escaping
Data Flow Analysis
Newsletter – Send awesome emails from WordPress Attack Surface
AJAX Handlers 15
Shortcodes 11
WordPress Hooks 69
Scheduled Events 7
Maintenance & Trust
Newsletter – Send awesome emails from WordPress Maintenance & Trust
Maintenance Signals
Community Trust
Newsletter – Send awesome emails from WordPress Alternatives
Newsletter Subscription Form – User Subscriptions Form, Capture Email
newsletter-subscription-form
Newsletter Subscription Form for WordPress is the ultimate lead generation, customer acquisition and email marketing plugin to grow and engage your ma …
Hostinger Reach – AI-Powered Email Marketing for WordPress
hostinger-reach
Launch and grow your email marketing effortlessly with Hostinger Reach. Collect contacts, sync subscribers, and send emails – all in one, AI powered.
Sender – Newsletter, SMS and Email Marketing Automation for WooCommerce
sender-net-automated-emails
Sender is an all-in-one email & SMS marketing platform designed keeping the challenges of ecommerce and small businesses in mind.
Constant Contact Forms by MailMunch
constant-contact-forms-by-mailmunch
The #1 Constant Contact plugin to get more email subscribers. Easily add Constant Contact sign-up forms as popup, embedded widget or sticky top bar.
SendPulse Email Marketing Newsletter
sendpulse-email-marketing-newsletter
Add a customizable email subscription form to your site, send newsletters, and automate email campaigns with autoresponders using SendPulse.
Newsletter – Send awesome emails from WordPress Developer Profile
14 plugins · 515K total installs
How We Detect Newsletter – Send awesome emails from WordPress
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/newsletter/assets/css/admin.css/wp-content/plugins/newsletter/assets/css/style.css/wp-content/plugins/newsletter/assets/js/admin.js/wp-content/plugins/newsletter/assets/js/front.js/wp-content/plugins/newsletter/assets/js/main.js/wp-content/plugins/newsletter/emails/emails.js/wp-content/plugins/newsletter/tnp-list.js/wp-content/plugins/newsletter/assets/js/main.js/wp-content/plugins/newsletter/assets/js/admin.js/wp-content/plugins/newsletter/assets/js/front.js/wp-content/plugins/newsletter/emails/emails.js/wp-content/plugins/newsletter/tnp-list.jsnewsletter/style.css?ver=newsletter/main.js?ver=newsletter/admin.js?ver=newsletter/front.js?ver=newsletter/emails/emails.js?ver=newsletter/tnp-list.js?ver=HTML / DOM Fingerprints
tnp-formtnp-fieldtnp-labeltnp-inputtnp-buttontnp-submittnp-texttnp-email+43 more<!-- Newsletter --><!-- Newsletter form --><!-- Newsletter plugin --><!-- END Newsletter -->+6 moredata-newsletter-iddata-newsletter-formdata-newsletter-fielddata-newsletter-noncedata-tnp-actiondata-tnp-nonce+2 moretnp_ajaxurltnp_dataNewsletter/wp-json/newsletter/v1/settings/wp-json/newsletter/v1/subscribers/wp-json/newsletter/v1/forms/wp-json/newsletter/v1/campaigns[newsletter][newsletter_replace]