VYPR

MDirector Newsletter

by WordPress

CVEs (1)

  • CVE-2025-14852MedFeb 14, 2026
    risk 0.21cvss 4.3epss 0.00

    The MDirector Newsletter plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 4.5.8. This is due to missing nonce verification on the mdirectorNewsletterSave function. This makes it possible for unauthenticated attackers to…