VYPR

Newsletters Lite

by WordPress

Source repositories

CVEs (30)

  • CVE-2026-16269MedAug 8, 2026
    risk 0.31cvss 4.8epss 0.00

    The Newsletters WordPress plugin before 4.16 does not strictly compare its API authentication key, allowing unauthenticated attackers to bypass the API authentication via type juggling and perform privileged actions such as modifying subscriber records and sending emails, when…

  • CVE-2025-54035MedJul 16, 2025
    risk 0.28cvss 4.3epss 0.00

    Cross-Site Request Forgery (CSRF) vulnerability in Tribulant Software Newsletters newsletters-lite allows Cross Site Request Forgery.This issue affects Newsletters: from n/a through <= 4.10.

  • CVE-2024-37227MedJun 21, 2024
    risk 0.28cvss 4.3epss 0.00

    Cross Site Request Forgery (CSRF) vulnerability in Tribulant Newsletters.This issue affects Newsletters: from n/a through 4.9.7.

  • CVE-2024-7411MedAug 15, 2024
    risk 0.27cvss 5.3epss 0.00

    The Newsletters plugin for WordPress is vulnerable to Full Path Disclosure in all versions up to, and including, 4.9.9. This is due the plugin not preventing direct access to the /vendor/mobiledetect/mobiledetectlib/export/exportToJSON.php. This makes it possible for…

  • CVE-2026-12939MedJul 29, 2026
    risk 0.00cvss 6.4epss 0.00

    The Newsletters Lite plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'link' attribute of the post_thumbnail (and newsletters_post_thumbnail) shortcodes in versions up to and including 4.15. This is due to insufficient input sanitization and output…

  • CVE-2026-12938MedJul 29, 2026
    risk 0.00cvss 6.4epss 0.00

    The Newsletters Lite plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'target' attribute of the [newsletters_post] shortcode in versions up to and including 4.15. This is due to insufficient input sanitization and output escaping in the posts_single()…

  • CVE-2026-12583HigJul 14, 2026
    risk 0.00cvss 8.1epss 0.00

    The Newsletters WordPress plugin before 4.15 does not prevent deserialization of untrusted input that is stored through a public form, allowing unauthenticated attackers to inject a PHP object and, via a property-oriented gadget chain bundled with the Newsletters WordPress…

  • CVE-2026-57394HigJul 13, 2026
    risk 0.00cvss 7.1epss 0.00

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Tribulant Software Newsletters newsletters-lite allows Reflected XSS.This issue affects Newsletters: from n/a through <= 4.14.

  • CVE-2026-57645HigJun 26, 2026
    risk 0.00cvss 8.1epss 0.00

    newsletters_subscribers Broken Access Control in Newsletters <= 4.13 versions.

  • CVE-2026-54840HigJun 26, 2026
    risk 0.00cvss 7.3epss 0.00

    Unauthenticated Broken Access Control in Newsletters <= 4.13 versions.

Page 2 of 2