CRITICAL 9.3 CVE-2026-41555 Published 6 Oct 2026

WordPress Newsletter Subscription Form Plugin SQL Injection Vulnerability

Worried this affects your website?

Newsletter Subscription Form – User Subscriptions Form, Capture Email is affected by an Unauthenticated SQL Injection vulnerability.

The flaw impacts versions 1.5.9 and earlier, allowing attackers to inject SQL queries through the newsletter subscription form without authentication.

Reference: CVE-2026-41555 on NVD

← Back to Security News