Newspack Newsletters <= 3.13.0 - Open Redirect
medium
The Newspack Newsletters plugin for WordPress is vulnerable to Open Redirect in all versions up to, and including, 3.13.0. This is due to insufficient validation on a redirect url. This makes it possible for unauthenticated attackers to redirect users to potentially malicious sites if they can successfully trick them i...
- CVSS:
- 6.1
- Affected:
- up to 3.13.0
- Fixed in:
- 3.14.0
- Disclosed:
- Jun 5, 2025
CVE-2025-49325 on NVD →
Newspack Newsletters <= 2.13.2 - Missing Authorization
medium
The Newspack Newsletters plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the api_content function in versions up to, and including, 2.13.2. This makes it possible for unauthenticated attackers to retrieve campaign information.
- CVSS:
- 5.3
- Affected:
- up to 2.13.2
- Fixed in:
- 2.13.3
- Disclosed:
- Jul 1, 2024
CVE-2024-37475 on NVD →
Newspack Newsletters <= 2.13.2 - Cross-Site Request Forgery
medium
The Newspack Newsletters plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.13.2. This is due to missing or incorrect nonce validation. This makes it possible for unauthenticated attackers to perform unauthorized actions via a forged request granted they can trick a sit...
- CVSS:
- 4.3
- Affected:
- up to 2.13.2
- Fixed in:
- 2.13.3
- Disclosed:
- Jun 21, 2024
CVE-2024-37242 on NVD →
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database