CVE-2025-3583

Newsletter < 8.7.1 - Admin+ Stored XSS

The Newsletter WordPress plugin before 8.7.1 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).


We have discovered 32,933 live websites that are affected by CVE-2025-3583.

Run a Free Instant Scan




Affected Software

Product  Newsletter
Category Wordpress Plugins
Vulnerable Domains32,933 live websites (39% of Newsletter install base)
Vulnerable Versions
  • from 0 through 8.7.1
Vulnerable Versions Count348 versions ( 91% of all versions)


Common Weakness Enumeration

CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')



Details

  • Published - May 5, 2025
  • Updated - May 5, 2025

Credits

  • Dmitrii Ignatyev (finder)
  • WPScan (coordinator)

Website Distribution by Country

Number of websites using CVE-2025-3583
United States7,221 websites



Germany4,662 websites
Italy2,845 websites
France2,610 websites
Poland1,419 websites
GB1,184 websites
Spain839 websites
Netherlands629 websites
Brazil601 websites
Russia591 websites

Website Distribution by TLD

Number of websites using CVE-2025-3583
.com12,248 websites
.de2,572 websites
.it1,952 websites
.org1,781 websites
.fr1,067 websites
.pl1,058 websites
.net682 websites
.co.uk578 websites
.com.br525 websites
.eu524 websites

Vulnerable Versions

Vulnerable versions are highlighted in red

Websites affected by CVE-2025-3583

Top websites that are affected by CVE-2025-3583. Please click on the "Contact us" link to get more information.
DomainCountryRankContacts
**********.com United States*,***
*********.com United States*,***
**************.com United States**,***
******.com United States**,***
**********.com United States**,***
**************.com United States**,***
********.org **,***
**********.com United States**,***
*******.org Germany**,***
***************.com United States**,***
See full domain list

FAQ

CVE-2025-3583 is Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in Newsletter
A total of 32,933 websites have been identified as vulnerable to CVE-2025-3583, based on global website indexing conducted by WebTechSurvey.
The Newsletter is affected by the CVE-2025-3583 vulnerability.
Newsletter versions up to 8.7.1 are vulnerable to CVE-2025-3583.
CVE-2025-3583 is resolved in version 8.7.1 of Newsletter.