VYPR

Newsletter

by Tribulant

CVEs (1)

  • CVE-2020-35932HigJan 1, 2021
    risk 0.49cvss 7.5epss 0.02

    Insecure Deserialization in the Newsletter plugin before 6.8.2 for WordPress allows authenticated remote attackers with minimal privileges (such as subscribers) to use the tpnc_render AJAX action to inject arbitrary PHP objects via the options[inline_edits] parameter. NOTE:…