📦 Newsletters

by Tribulant

🔍 What is Newsletters?

Description coming soon...

🛡️ Security Overview

Click on a severity to filter vulnerabilities

⚠️ Known Vulnerabilities

CVE-2025-4857

HIGH CVSS 7.2 May 31, 2025

The Newsletters plugin for WordPress contains a Local File Inclusion vulnerability that allows authenticated attackers with Administrator privileges to include and execute arbitrary PHP files on the s...

CVE-2024-8247

HIGH CVSS 8.8 Sep 6, 2024

The Newsletters plugin for WordPress allows authenticated users with subscriber-level access or higher to escalate privileges to administrator by manipulating user meta through screen options. This af...

CVE-2024-35718

HIGH CVSS 7.1 Jun 8, 2024

This vulnerability allows attackers to inject malicious scripts into web pages generated by the Tribulant Newsletters WordPress plugin. When users view these pages, the scripts execute in their browse...

CVE-2023-4797

HIGH CVSS 7.2 Jan 16, 2024

This vulnerability in the Newsletters WordPress plugin allows administrators to execute arbitrary SQL queries and shell commands on the server due to improper input escaping. It affects WordPress site...

CVE-2024-13739

MEDIUM CVSS 6.1 Mar 22, 2025

This vulnerability allows unauthenticated attackers to inject malicious scripts via the 'to' parameter in the WordPress Newsletters plugin. When an administrator clicks a specially crafted link, the s...

CVE-2024-10181

MEDIUM CVSS 6.4 Oct 29, 2024

The Newsletters plugin for WordPress has a stored XSS vulnerability in its newsletters_video shortcode. Authenticated attackers with contributor-level access or higher can inject malicious scripts tha...