What is CVE-2026-12938?
The 'Newsletters Lite' plugin for WordPress up to version 4.15 is vulnerable to Stored Cross-Site Scripting via the 'target' attribute of the [newsletters_post] shortcode due to insufficient input sanitization and output escaping in the posts_single() function. This allows attackers to inject malicious scripts, and users should update the plugin to the latest version immediately.
Azərbaycanca: Bu zəiflik WordPress-in 'Newsletters Lite' plagininin 4.15 və daha əvvəlki versiyalarında [newsletters_post] qısa kodunun 'target' atributu vasitəsilə Stored Cross-Site Scripting (XSS) hücumuna imkan verir. Bu, posts_single() funksiyasında kifayət qədər input sanitization və output escaping olmaması səbəbindən baş verir, təcavüzkara zərərli skriptin saxlanmasına şərait yaradır. Plagin istifadəçiləri dərhal ən son versiyaya yeniləməlidir.
Related CVEs
link basis: same weakness class CWE-79
FAQ2
Which versions of the WordPress 'Newsletters Lite' plugin are affected by CVE-2026-12938?
This vulnerability affects the plugin up to and including version 4.15.
What type of attack can an attacker perform by exploiting CVE-2026-12938?
An attacker can perform a Stored Cross-Site Scripting (XSS) attack via the 'target' attribute of the [newsletters_post] shortcode.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.