Newsletters <= 4.17 - Missing Authorization to Authenticated (Author+) Arbitrary Modification via 'newsletters_mailinglistsroles' POST Parameter
medium
The Newsletters plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 4.17. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for authenticated attackers, with author-level access and above, to send arbitrar...
- CVSS:
- 4.3
- Affected:
- up to 4.17
- Fixed in:
- 4.18
- Disclosed:
- Aug 24, 2026
CVE-2026-75908 on NVD →
Newsletters <= 4.15 - Unauthenticated PHP Object Injection
high
The Newsletters plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 4.15 via deserialization of untrusted input. This makes it possible for unauthenticated attackers to inject a PHP Object. No known POP chain is present in the vulnerable software. If a POP chain is present via a...
- CVSS:
- 8.1
- Affected:
- up to 4.15
- Fixed in:
- 4.16
- Disclosed:
- Aug 3, 2026
CVE-2026-16267 on NVD →
Newsletters <= 4.15 - Unauthenticated Server-Side Request Forgery
high
The Newsletters plugin for WordPress is vulnerable to Server-Side Request Forgery in versions up to, and including, 4.15. This is due to missing validation of the SubscribeURL hostname before issuing a remote request in the SNS bounce handler, allowing arbitrary URLs to be requested via wp_remote_request. This makes it...
- CVSS:
- 7.2
- Affected:
- up to 4.15
- Fixed in:
- 4.16
- Disclosed:
- Jul 30, 2026
CVE-2026-16268 on NVD →
Newsletters <= 4.15 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'link' Shortcode Attribute
medium
The Newsletters Lite plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'link' attribute of the post_thumbnail (and newsletters_post_thumbnail) shortcodes in versions up to and including 4.15. This is due to insufficient input sanitization and output escaping in the post_thumbnail() method in hel...
- CVSS:
- 6.4
- Affected:
- up to 4.15
- Fixed in:
- 4.16
- Disclosed:
- Jul 28, 2026
CVE-2026-12939 on NVD →
Newsletters <= 4.15 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'target' Shortcode Attribute
medium
The Newsletters Lite plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'target' attribute of the [newsletters_post] shortcode in versions up to and including 4.15. This is due to insufficient input sanitization and output escaping in the posts_single() function which propagates the attacker-cont...
- CVSS:
- 6.4
- Affected:
- up to 4.15
- Fixed in:
- 4.16
- Disclosed:
- Jul 28, 2026
CVE-2026-12938 on NVD →
Newsletters <= 4.14 - Unauthenticated Stored Cross-Site Scripting
high
The Newsletters plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 4.14 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an...
- CVSS:
- 7.2
- Affected:
- up to 4.14
- Fixed in:
- 4.15
- Disclosed:
- Jul 8, 2026
CVE-2026-57394 on NVD →
Newsletters <= 4.13 - Missing Authorization
medium
The Newsletters plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in versions up to, and including, 4.13. This makes it possible for authenticated attackers, with newsletters_subscribers-level access and above, to perform an unauthorized action.
- CVSS:
- 4.3
- Affected:
- up to 4.13
- Fixed in:
- 4.14
- Disclosed:
- Jun 26, 2026
CVE-2026-57645 on NVD →
Newsletters <= 4.14 - Unauthenticated PHP Object Injection
high
The Newsletters plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 4.14 via deserialization of untrusted input. This makes it possible for unauthenticated attackers to inject a PHP Object. No known POP chain is present in the vulnerable software. If a POP chain is present via a...
- CVSS:
- 8.1
- Affected:
- up to 4.14
- Fixed in:
- 4.15
- Disclosed:
- Jun 23, 2026
CVE-2026-12583 on NVD →
Newsletters <= 4.13 - Missing Authorization
medium
The Newsletters plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in versions up to, and including, 4.13. This makes it possible for unauthenticated attackers to perform an unauthorized action.
- CVSS:
- 5.3
- Affected:
- up to 4.13
- Fixed in:
- 4.14
- Disclosed:
- Jun 18, 2026
CVE-2026-54840 on NVD →
Newsletters <= 4.13 - Unauthenticated SQL Injection via wpmlsubscriber_id Parameter
high
The Newsletters plugin for WordPress is vulnerable to time-based SQL Injection via the ‘wpmlsubscriber_id’ parameter in all versions up to, and including, 4.13 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenti...
- CVSS:
- 7.5
- Affected:
- up to 4.13
- Fixed in:
- 4.14
- Disclosed:
- Jun 9, 2026
CVE-2026-3018 on NVD →
Newsletters [newsletters-lite] <= 4.11 (unfixed)
unknown
[en] Deserialization of Untrusted Data vulnerability in Tribulant Software Newsletters newsletters-lite allows Object Injection.This issue affects Newsletters: from n/a through <= 4.11.
- Affected:
- up to 4.11
- Fix:
- No patched version reported
- Disclosed:
- Jan 8, 2026
CVE-2025-67911 on NVD →
Newsletters <= 4.11 - Unauthenticated PHP Object Injection
high
The Newsletters plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 4.11 via deserialization of untrusted input. This makes it possible for unauthenticated attackers to inject a PHP Object. No known POP chain is present in the vulnerable software. If a POP chain is present via a...
- CVSS:
- 8.1
- Affected:
- up to 4.11
- Fixed in:
- 4.12
- Disclosed:
- Dec 31, 2025
CVE-2025-67911 on NVD →
Newsletters [newsletters-lite] <= 4.12 (unfixed)
unknown
[en] Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Tribulant Software Newsletters newsletters-lite allows Stored XSS.This issue affects Newsletters: from n/a through <= 4.12.
- Affected:
- up to 4.12
- Fix:
- No patched version reported
- Disclosed:
- Dec 30, 2025
CVE-2025-69020 on NVD →
Newsletters <= 4.12 - Authenticated (Contributor+) Stored Cross-Site Scripting
medium
The Newsletters plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 4.12 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that...
- CVSS:
- 6.4
- Affected:
- up to 4.12
- Fixed in:
- 4.13
- Disclosed:
- Dec 28, 2025
CVE-2025-69020 on NVD →
Newsletters [newsletters-lite] < 4.11
unknown
[en] Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Tribulant Software Newsletters allows PHP Local File Inclusion. This issue affects Newsletters: from n/a through 4.10.
- Affected:
- up to 4.11
- Fixed in:
- 4.11
- Disclosed:
- Aug 20, 2025
CVE-2025-54034 on NVD →
Newsletters <= 4.10 - Unauthenticated Local File Inclusion
high
The Newsletters plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 4.10. This makes it possible for unauthenticated attackers to include and execute arbitrary files on the server, allowing the execution of any PHP code in those files. This can be used to bypass access contr...
- CVSS:
- 8.1
- Affected:
- up to 4.10
- Fixed in:
- 4.11
- Disclosed:
- Jul 29, 2025
CVE-2025-54034 on NVD →
Newsletters <= 4.10 - Cross-Site Request Forgery
medium
The Newsletters plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 4.10. This is due to missing or incorrect nonce validation on a function. This makes it possible for unauthenticated attackers to perform an unauthorized action granted they can trick a site administra...
- CVSS:
- 4.3
- Affected:
- up to 4.10
- Fixed in:
- 4.11
- Disclosed:
- Jul 16, 2025
CVE-2025-54035 on NVD →
Newsletters [newsletters-lite] < 4.11
unknown
[en] Cross-Site Request Forgery (CSRF) vulnerability in Tribulant Software Newsletters allows Cross Site Request Forgery. This issue affects Newsletters: from n/a through 4.10.
- Affected:
- up to 4.11
- Fixed in:
- 4.11
- Disclosed:
- Jul 16, 2025
CVE-2025-54035 on NVD →
Newsletters <= 4.9.9.9 - Authenticated (Administrator+) Local File Inclusion
high
The Newsletters plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 4.9.9.9 via the 'file' parameter. This makes it possible for authenticated attackers, with Administrator-level access and above, to include and execute arbitrary files on the server, allowing the execution o...
- CVSS:
- 7.2
- Affected:
- up to 4.9.9.9
- Fixed in:
- 4.10
- Disclosed:
- May 30, 2025
CVE-2025-4857 on NVD →
Newsletters <= 4.9.9.8 - Authenticated (Contributor+) SQL Injection orderby Parameter
medium
The Newsletters plugin for WordPress is vulnerable to time-based SQL Injection via the ‘orderby' parameter in all versions up to, and including, 4.9.9.8 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated att...
- CVSS:
- 6.5
- Affected:
- up to 4.9.9.8
- Fixed in:
- 4.9.9.9
- Disclosed:
- May 12, 2025
CVE-2025-3107 on NVD →
Newsletters <= 4.9.9.7 - Authenticated (Administrator+) SQL Injection
medium
The Newsletters plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 4.9.9.7 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with administrator-level access and...
- CVSS:
- 4.9
- Affected:
- up to 4.9.9.7
- Fixed in:
- 4.9.9.8
- Disclosed:
- Mar 27, 2025
CVE-2025-30921 on NVD →
Newsletters [newsletters-lite] < 4.9.9.8
unknown
[en] Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Tribulant Software Newsletters allows SQL Injection. This issue affects Newsletters: from n/a through 4.9.9.7.
- Affected:
- up to 4.9.9.8
- Fixed in:
- 4.9.9.8
- Disclosed:
- Mar 27, 2025
CVE-2025-30921 on NVD →
Newsletters <= 4.9.9.7 - Unauthenticated Stored Cross-Site Scripting
high
The Newsletters plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the logging functionality in all versions up to, and including, 4.9.9.7 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that wil...
- CVSS:
- 7.2
- Affected:
- up to 4.9.9.7
- Fixed in:
- 4.9.9.8
- Disclosed:
- Mar 25, 2025
CVE-2025-2009 on NVD →
Newsletters [newsletters-lite] < 4.9.9.8
unknown
[en] The Newsletters plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the "to" parameter in all versions up to, and including, 4.9.9.7 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that ex...
- Affected:
- up to 4.9.9.8
- Fixed in:
- 4.9.9.8
- Disclosed:
- Mar 22, 2025
CVE-2024-13739 on NVD →
Newsletters <= 4.9.9.7 - Reflected Cross-Site Scripting via To Parameter
medium
The Newsletters plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the "to" parameter in all versions up to, and including, 4.9.9.7 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute...
- CVSS:
- 6.1
- Affected:
- up to 4.9.9.7
- Fixed in:
- 4.9.9.8
- Disclosed:
- Mar 21, 2025
CVE-2024-13739 on NVD →
Newsletters [newsletters-lite] < 4.9.9.7
unknown
[en] Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Tribulant Newsletters allows Reflected XSS. This issue affects Newsletters: from n/a through 4.9.9.6.
- Affected:
- up to 4.9.9.7
- Fixed in:
- 4.9.9.7
- Disclosed:
- Feb 4, 2025
CVE-2025-24599 on NVD →
Newsletters <= 4.9.9.6 - Reflected Cross-Site Scripting
medium
The Newsletters plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in all versions up to, and including, 4.9.9.6 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successful...
- CVSS:
- 6.1
- Affected:
- up to 4.9.9.6
- Fixed in:
- 4.9.9.7
- Disclosed:
- Dec 26, 2024
CVE-2025-24599 on NVD →
Newsletters [newsletters-lite] < 4.9.9.5
unknown
[en] The Newsletters plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's newsletters_video shortcode in all versions up to, and including, 4.9.9.4 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, wi...
- Affected:
- up to 4.9.9.5
- Fixed in:
- 4.9.9.5
- Disclosed:
- Oct 29, 2024
CVE-2024-10181 on NVD →
Newsletters <= 4.9.9.4 - Authenticated (Contributor+) Stored Cross-Site Scripting via newsletters_video Shortcode
medium
The Newsletters plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's newsletters_video shortcode in all versions up to, and including, 4.9.9.4 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with co...
- CVSS:
- 6.4
- Affected:
- up to 4.9.9.4
- Fixed in:
- 4.9.9.5
- Disclosed:
- Oct 28, 2024
CVE-2024-10181 on NVD →
Newsletters [newsletters-lite] < 4.9.9.2
unknown
[en] Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Tribulant Newsletters allows Reflected XSS.This issue affects Newsletters: from n/a through 4.9.9.1.
- Affected:
- up to 4.9.9.2
- Fixed in:
- 4.9.9.2
- Disclosed:
- Oct 6, 2024
CVE-2024-47346 on NVD →
Newsletters <= 4.9.9.1 - Reflected Cross-Site Scripting
medium
The Newsletters plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 4.9.9.1 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully t...
- CVSS:
- 6.1
- Affected:
- up to 4.9.9.1
- Fixed in:
- 4.9.9.2
- Disclosed:
- Sep 27, 2024
CVE-2024-47346 on NVD →
Newsletters [newsletters-lite] < 4.9.9.3
unknown
[en] The Newsletters plugin for WordPress is vulnerable to privilege escalation in all versions up to, and including, 4.9.9.2. This is due to the plugin not restricting what user meta can be updated as screen options. This makes it possible for authenticated attackers, with subscriber-level access and above, to escalat...
- Affected:
- up to 4.9.9.3
- Fixed in:
- 4.9.9.3
- Disclosed:
- Sep 6, 2024
CVE-2024-8247 on NVD →
Newsletters <= 4.9.9.2 - Authenticated Privilege Escalation
high
The Newsletters plugin for WordPress is vulnerable to privilege escalation in all versions up to, and including, 4.9.9.2. This is due to the plugin not restricting what user meta can be updated as screen options. This makes it possible for authenticated attackers, with subscriber-level access and above, to escalate the...
- CVSS:
- 8.8
- Affected:
- up to 4.9.9.2
- Fixed in:
- 4.9.9.3
- Disclosed:
- Sep 5, 2024
CVE-2024-8247 on NVD →
Newsletters [newsletters-lite] < 4.9.9
unknown
[en] Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Tribulant Newsletters allows Reflected XSS.This issue affects Newsletters: from n/a through 4.9.8.
- Affected:
- up to 4.9.9
- Fixed in:
- 4.9.9
- Disclosed:
- Aug 18, 2024
CVE-2024-43279 on NVD →
Newsletters <= 4.9.8 - Reflected Cross-Site Scripting
medium
The Newsletters plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in all versions up to, and including, 4.9.8 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully...
- CVSS:
- 6.1
- Affected:
- up to 4.9.8
- Fixed in:
- 4.9.9
- Disclosed:
- Aug 16, 2024
CVE-2024-43279 on NVD →
Newsletters [newsletters-lite] < 4.9.9.1
unknown
[en] The Newsletters plugin for WordPress is vulnerable to Full Path Disclosure in all versions up to, and including, 4.9.9. This is due the plugin not preventing direct access to the /vendor/mobiledetect/mobiledetectlib/export/exportToJSON.php. This makes it possible for unauthenticated attackers to retrieve the full...
- Affected:
- up to 4.9.9.1
- Fixed in:
- 4.9.9.1
- Disclosed:
- Aug 15, 2024
CVE-2024-7411 on NVD →
Newsletters <= 4.9.9 - Unauthenticated Full Path Disclosure
medium
The Newsletters plugin for WordPress is vulnerable to Full Path Disclosure in all versions up to, and including, 4.9.9. This is due the plugin not preventing direct access to the /vendor/mobiledetect/mobiledetectlib/export/exportToJSON.php. This makes it possible for unauthenticated attackers to retrieve the full path...
- CVSS:
- 5.3
- Affected:
- up to 4.9.9
- Fixed in:
- 4.9.9.1
- Disclosed:
- Aug 14, 2024
CVE-2024-7411 on NVD →
Newsletters <= 4.9.7 - Cross-Site Request Forgery
medium
The Newsletters plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 4.9.7. This is due to missing or incorrect nonce validation on the admin_subscribers() function. This makes it possible for unauthenticated attackers to delete an unsubscribe subscribers via a forged reque...
- CVSS:
- 4.3
- Affected:
- up to 4.9.7
- Fixed in:
- 4.9.8
- Disclosed:
- Jun 21, 2024
CVE-2024-37227 on NVD →
Newsletters [newsletters-lite] < 4.9.8
unknown
[en] Cross Site Request Forgery (CSRF) vulnerability in Tribulant Newsletters.This issue affects Newsletters: from n/a through 4.9.7.
- Affected:
- up to 4.9.8
- Fixed in:
- 4.9.8
- Disclosed:
- Jun 21, 2024
CVE-2024-37227 on NVD →
Newsletters [newsletters-lite] < 4.9.6
unknown
[en] Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Tribulant Newsletters allows Reflected XSS.This issue affects Newsletters: from n/a through 4.9.5.
- Affected:
- up to 4.9.6
- Fixed in:
- 4.9.6
- Disclosed:
- Jun 8, 2024
CVE-2024-35718 on NVD →
Newsletters <= 4.9.5 - Reflected Cross-Site Scripting
medium
The Newsletters plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in all versions up to, and including, 4.9.5 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully...
- CVSS:
- 6.1
- Affected:
- up to 4.9.5
- Fixed in:
- 4.9.6
- Disclosed:
- Jun 6, 2024
CVE-2024-35718 on NVD →
Newsletters [newsletters-lite] < 4.9.6
unknown
[en] Unrestricted Upload of File with Dangerous Type vulnerability in Tribulant Newsletters.This issue affects Newsletters: from n/a through 4.9.5.
- Affected:
- up to 4.9.6
- Fixed in:
- 4.9.6
- Disclosed:
- Apr 24, 2024
CVE-2024-32954 on NVD →
Newsletters [newsletters-lite] < 4.9.6
unknown
[en] Insertion of Sensitive Information into Log File vulnerability in Newsletters.This issue affects Newsletters: from n/a through 4.9.5.
- Affected:
- up to 4.9.6
- Fixed in:
- 4.9.6
- Disclosed:
- Apr 24, 2024
CVE-2024-32953 on NVD →
Newsletters <= 4.9.5 - Authenticated (Admin+) Arbitrary File Upload
critical
The Newsletters plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in all versions up to, and including, 4.9.5. This makes it possible for authenticated attackers, with administrator-level access and above, to upload arbitrary files on the affected site's server which may m...
- CVSS:
- 9.1
- Affected:
- up to 4.9.5
- Fixed in:
- 4.9.6
- Disclosed:
- Apr 22, 2024
CVE-2024-32954 on NVD →
Newsletters <= 4.9.5 - Information Exposure via Log files
medium
The Newsletters plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 4.9.5. This makes it possible for unauthenticated attackers to extract potentially sensitive information from log files.
- CVSS:
- 5.3
- Affected:
- up to 4.9.5
- Fixed in:
- 4.9.6
- Disclosed:
- Apr 22, 2024
CVE-2024-32953 on NVD →
Newsletters [newsletters-lite] < 4.9.3
unknown
[en] The Newsletters WordPress plugin before 4.9.3 does not properly escape user-controlled parameters when they are appended to SQL queries and shell commands, which could enable an administrator to run arbitrary commands on the server.
- Affected:
- up to 4.9.3
- Fixed in:
- 4.9.3
- Disclosed:
- Jan 16, 2024
CVE-2023-4797 on NVD →
Newsletters [newsletters-lite] < 4.9.9
unknown
[en] Cross-Site Request Forgery (CSRF) vulnerability in Tribulant Newsletters plugin <= 4.8.8 versions.
- Affected:
- up to 4.9.9
- Fixed in:
- 4.9.9
- Disclosed:
- Nov 10, 2023
CVE-2023-30478 on NVD →
Newsletter Lite <= 4.9.2 - Authenticated (Admin+) Command Injection
medium
The Newsletters plugin for WordPress is vulnerable to Command Injection in all versions up to, and including, 4.9.2 via the emailarchive_olderthan parameter. This is due to insuffcient validation on user supplied input being passed to eval. This makes it possible for authenticated attackers, with administrator-level ac...
- CVSS:
- 6.6
- Affected:
- up to 4.9.2
- Fixed in:
- 4.9.3
- Disclosed:
- Oct 5, 2023
CVE-2023-4797 on NVD →
Newsletters <= 4.8.8 - Cross-Site Request Forgery
medium
The Newsletters plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 4.8.8. This is due to missing nonce validation on several cases in several functions like admin_groups() and admin_forms(). This makes it possible for unauthenticated attackers to manipulate forms and grou...
- CVSS:
- 5.4
- Affected:
- up to 4.8.8
- Fixed in:
- 4.8.9
- Disclosed:
- Apr 13, 2023
CVE-2023-30478 on NVD →
Newsletters [newsletters-lite] < 4.6.8.6
unknown
[en] The newsletters-lite plugin before 4.6.8.6 for WordPress has PHP object injection.
- Affected:
- up to 4.6.8.6
- Fixed in:
- 4.6.8.6
- Disclosed:
- Aug 22, 2019
CVE-2018-20987 on NVD →
Newsletters [newsletters-lite] < 4.6.19
unknown
[en] wp-admin/admin-ajax.php?action=newsletters_exportmultiple in the Tribulant Newsletters plugin before 4.6.19 for WordPress allows directory traversal with resultant remote PHP code execution via the subscribers[1][1] parameter in conjunction with an exportfile=../ value.
- Affected:
- up to 4.6.19
- Fixed in:
- 4.6.19
- Disclosed:
- Aug 15, 2019
CVE-2019-14788 on NVD →
Newsletters [newsletters-lite] < 4.6.19
unknown
[en] The Tribulant Newsletters plugin before 4.6.19 for WordPress allows XSS via the wp-admin/admin-ajax.php?action=newsletters_load_new_editor contentarea parameter.
- Affected:
- up to 4.6.19
- Fixed in:
- 4.6.19
- Disclosed:
- Aug 9, 2019
CVE-2019-14787 on NVD →
Newsletters [newsletters-lite] < 4.6.18
unknown
Authenticated Reflected Cross-Site Scripting (XSS) vulnerability found in WordPress Newsletter Lite plugin (versions <= 4.6.16).
- Affected:
- up to 4.6.18
- Fixed in:
- 4.6.18
- Disclosed:
- Jul 11, 2019
Newsletters <= 4.6.18 - Directory Traversal
high
wp-admin/admin-ajax.php?action=newsletters_exportmultiple in the Tribulant Newsletters plugin before 4.6.19 for WordPress allows directory traversal with resultant remote PHP code execution via the subscribers[1][1] parameter in conjunction with an exportfile=../ value.
- CVSS:
- 8.8
- Affected:
- up to 4.6.19
- Fixed in:
- 4.6.19
- Disclosed:
- Jul 1, 2019
CVE-2019-14788 on NVD →
Newsletters <= 4.6.18 - Cross-Site Scripting via contentarea Parameter
medium
The Tribulant Newsletters plugin before 4.6.19 for WordPress allows XSS via the wp-admin/admin-ajax.php?action=newsletters_load_new_editor contentarea parameter.
- CVSS:
- 5.4
- Affected:
- up to 4.6.19
- Fixed in:
- 4.6.19
- Disclosed:
- Jul 1, 2019
CVE-2019-14787 on NVD →
Newsletters <= 4.6.8.5 - Object Injection
critical
The newsletters-lite plugin before 4.6.8.6 for WordPress has PHP object injection.
- CVSS:
- 9.8
- Affected:
- up to 4.6.8.6
- Fixed in:
- 4.6.8.6
- Disclosed:
- Mar 12, 2018
CVE-2018-20987 on NVD →
Newsletters <= 4.6.4.2 - Reflected Cross-Site Scripting
medium
The Newsletters for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘id’, 'method', 'value', 'order', 'wpmlsearchterm', and 'wpmlmessage' parameters in versions up to, and including, 4.6.4.2 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attacke...
- CVSS:
- 5.4
- Affected:
- up to 4.6.5.2
- Fixed in:
- 4.6.5.3
- Disclosed:
- May 29, 2017
Newsletters <= 4.6.4.2 - Directory Traversal
medium
The Newsletters plugin for WordPress is vulnerable to directory traversal due to insufficient validation on the data supplied via the 'file' parameter in versions up to, and including 4.6.4.2. This makes it possible for authenticated attackers to access arbitrary files on the system.
- CVSS:
- 4.9
- Affected:
- up to 4.6.4.2
- Fixed in:
- 4.6.4.3
- Disclosed:
- May 29, 2017
Newsletters [newsletters-lite] < 4.6.4.3
unknown
The Newsletters plugin for WordPress is vulnerable to directory traversal due to insufficient validation on the data supplied via the 'file' parameter in versions up to, and including 4.6.4.2. This makes it possible for authenticated attackers to access arbitrary files on the system.
- Affected:
- up to 4.6.4.3
- Fixed in:
- 4.6.4.3
- Disclosed:
- May 29, 2017
Newsletters [newsletters-lite] < 4.6.5.3
unknown
The Newsletters for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘id’, 'method', 'value', 'order', 'wpmlsearchterm', and 'wpmlmessage' parameters in versions up to, and including, 4.6.4.2 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attacke...
- Affected:
- up to 4.6.5.3
- Fixed in:
- 4.6.5.3
- Disclosed:
- May 29, 2017
Newsletters [newsletters-lite] < 4.6.5
unknown
WordPress Tribulant Newsletters plugin version 4.6.4.2 and earlier are prone to File Disclosure vulnerability. Vulnerability found by Neven Biruski (DefenseCode).
Update WordPress Tribulant Newsletters plugin to the latest available version.
- Affected:
- up to 4.6.5
- Fixed in:
- 4.6.5
- Disclosed:
- May 29, 2017
Newsletters [newsletters-lite] < 4.6.5
unknown
WordPress Tribulant Newsletters plugin 4.6.4.2 and earlier versions vulnerable to Cross-Site Scripting (XSS). Vulnerabilities found by Neven Biruski (DefenseCode).
Update WordPress Tribulant Newsletters plugin to the latest available version.
- Affected:
- up to 4.6.5
- Fixed in:
- 4.6.5
- Disclosed:
- May 29, 2017
Newsletters [newsletters-lite] < 4.6.5
unknown
The Newsletters WordPress plugin was affected by security vulnerability.
- Affected:
- up to 4.6.5
- Fixed in:
- 4.6.5
Newsletters [newsletters-lite] < 4.10
unknown
- Affected:
- up to 4.10
- Fixed in:
- 4.10
CVE-2025-4857 on NVD →
Newsletters [newsletters-lite] < 4.9.9.9
unknown
- Affected:
- up to 4.9.9.9
- Fixed in:
- 4.9.9.9
CVE-2025-3107 on NVD →
Newsletters [newsletters-lite] < 4.9.9.5
unknown
- Affected:
- up to 4.9.9.5
- Fixed in:
- 4.9.9.5
Newsletters [newsletters-lite] < 4.9.9.8
unknown
- Affected:
- up to 4.9.9.8
- Fixed in:
- 4.9.9.8
CVE-2025-2009 on NVD →