CRITICAL
9.3 CVE-2026-41555 Published 6 Oct 2026
WordPress Newsletter Subscription Form Plugin SQL Injection Vulnerability
Worried this affects your website?
Newsletter Subscription Form – User Subscriptions Form, Capture Email is affected by an Unauthenticated SQL Injection vulnerability.
The flaw impacts versions 1.5.9 and earlier, allowing attackers to inject SQL queries through the newsletter subscription form without authentication.
Reference: CVE-2026-41555 on NVD
← Back to Security News