The Newsletter WordPress plugin before 8.7.1 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).
We have discovered 32,933 live websites that are affected by CVE-2025-3583.
| Product | |
| Category | Wordpress Plugins |
| Vulnerable Domains | 32,933 live websites (39% of Newsletter install base) |
| Vulnerable Versions |
|
| Vulnerable Versions Count | 348 versions ( 91% of all versions) |
| 7,221 websites | |
| 4,662 websites | |
| 2,845 websites | |
| 2,610 websites | |
| 1,419 websites | |
| 1,184 websites | |
| 839 websites | |
| 629 websites | |
| 601 websites | |
| 591 websites |
| .com | 12,248 websites |
| .de | 2,572 websites |
| .it | 1,952 websites |
| .org | 1,781 websites |
| .fr | 1,067 websites |
| .pl | 1,058 websites |
| .net | 682 websites |
| .co.uk | 578 websites |
| .com.br | 525 websites |
| .eu | 524 websites |
| Domain | Country | Rank | Contacts |
|---|---|---|---|
| **********.com | *,*** | ||
| *********.com | *,*** | ||
| **************.com | **,*** | ||
| ******.com | **,*** | ||
| **********.com | **,*** | ||
| **************.com | **,*** | ||
| ********.org | **,*** | ||
| **********.com | **,*** | ||
| *******.org | **,*** | ||
| ***************.com | **,*** |
FAQ