Newsletters 4.16 Release Notes

Release notes for version 4.16 of the WordPress Newsletter plugin.

This is a small update. We are preparing a larger v5.0 update with new features and improvements. Coming soon!

Fixed

  • Fixed CVE-2026-12938 stored XSS through the `target` attribute of post shortcodes by validating link targets and escaping them on output.
  • Fixed CVE-2026-12939 stored XSS through the `link` attribute of post thumbnail shortcodes by escaping URLs on output.
  • Fixed broken access control in subscriber management AJAX handlers by requiring the requested subscriber ID to match the authenticated management subscriber session before reading or updating profile and subscription data.
  • Fixed unauthenticated PHP object injection through public subscribe form date fields by preventing request-supplied values from being unserialized and disabling class instantiation when formatting stored serialized date values. Reported by Sai Praneeth Koti.
  • Fixed unauthenticated blind SSRF in the Amazon SNS bounce handler by verifying SNS message signatures, restricting SNS URLs to HTTPS AWS SNS hosts, and using safe remote requests. Reported by Yaswanth Reddy Sunkara.
  • Fixed API authentication bypass caused by loose API key comparison by requiring a non-empty string key and validating it with hash_equals(). Reported by Haitam Lazaar.

Beautiful Newsletter Templates

Professional newsletter templates that are fully responsive for desktop, tablet, and mobile. They are 100% cross-client compatible.

See Them

Pin It on Pinterest