BlossomThemes Email Newsletter
BlossomThemes Email Newsletter has 2 disclosed vulnerabilities in the WordSec catalog, reported between 2023 and 2024; all 2 are fixed as of September 2026. Their average CVSS score is 5.4, and the most serious one scores 5.5 out of 10.
The most common weakness is Missing Authorization, behind 1 of the records (50%). Other recurring categories include Server-Side Request Forgery (SSRF).
Every one of the 2 issues recorded for BlossomThemes Email Newsletter has a vendor fix available, so running the current release closes all known holes.
2 independent researchers contributed these findings, one record each. BlossomThemes Email Newsletter is installed on roughly 20,000 WordPress sites, so each unpatched flaw has a wide blast radius. The current release is tested up to WordPress 6.7.7.
CVE-2024-37098BlossomThemes Email Newsletter <= 2.2.6 - Authenticated (Admin+) Server-Side Request Forgery
Read the full analysisVulnerability Records

BlossomThemes Email Newsletter
Author
Blossom Themes
BlossomThemes Email Newsletter allows you to add email subscription form on your website. The plugin works best with BlossomThemes’ themes. Adding Subscription Form has never been this easy. Choose an email platform, enter your API key, choose an email list, and start getting new subscribers to your website. The plugin supports Sendinblue, MailChimp, MailerLite, ConvertKit, GetResponse, ActiveCampaign, AWeber. You can create any number of Newsletter forms and display them using a shortcode, popup and/or a widget. Once installed, the plugin page will appear on the Admin dashboard. Key Features and Highlights Unlimited newsletters and subscribers with statistics Supports Sendinblue, MailChimp, MailerLite, ConvertKit, GetResponse, ActiveCampaign and AWeber Display newsletter forms using a shortcode, popup and/or a widget Lists/Campaigns updates via AJAX Multi-list or single-list targeting in individual newsletter Form submission via AJAX, allowing a seamless user experience without page refreshes Background Image, Background Color and Font Color support
Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C