VYPR

Newsletters Lite

by WordPress

Source repositories

CVEs (34)

  • CVE-2025-3107MedMay 13, 2025
    risk 0.35cvss 6.5epss 0.00

    The Newsletters plugin for WordPress is vulnerable to time-based SQL Injection via the ‘orderby' parameter in all versions up to, and including, 4.9.9.8 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. …

  • CVE-2024-10181MedOct 29, 2024
    risk 0.35cvss 6.4epss 0.00

    The Newsletters plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's newsletters_video shortcode in all versions up to, and including, 4.9.9.4 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it…

  • CVE-2026-17520MedAug 29, 2026
    risk 0.31cvss 4.8epss 0.00

    The Newsletters WordPress plugin before 4.17 does not generate its API key using a sufficiently random source, deriving it from a publicly known value, allowing unauthenticated attackers to compute the key and perform privileged actions such as adding and deleting subscribers…

  • CVE-2026-16269MedAug 8, 2026
    risk 0.31cvss 4.8epss 0.00

    The Newsletters WordPress plugin before 4.16 does not strictly compare its API authentication key, allowing unauthenticated attackers to bypass the API authentication via type juggling and perform privileged actions such as modifying subscriber records and sending emails, when…

  • CVE-2026-75908MedAug 25, 2026
    risk 0.28cvss 4.3epss 0.00

    The Newsletters plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 4.17. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for authenticated attackers, with…

  • CVE-2025-54035MedJul 16, 2025
    risk 0.28cvss 4.3epss 0.00

    Cross-Site Request Forgery (CSRF) vulnerability in Tribulant Software Newsletters newsletters-lite allows Cross Site Request Forgery.This issue affects Newsletters: from n/a through <= 4.10.

  • CVE-2024-37227MedJun 21, 2024
    risk 0.28cvss 4.3epss 0.00

    Cross Site Request Forgery (CSRF) vulnerability in Tribulant Newsletters.This issue affects Newsletters: from n/a through 4.9.7.

  • CVE-2024-7411MedAug 15, 2024
    risk 0.27cvss 5.3epss 0.00

    The Newsletters plugin for WordPress is vulnerable to Full Path Disclosure in all versions up to, and including, 4.9.9. This is due the plugin not preventing direct access to the /vendor/mobiledetect/mobiledetectlib/export/exportToJSON.php. This makes it possible for…

  • CVE-2026-12939MedJul 29, 2026
    risk 0.00cvss 6.4epss 0.00

    The Newsletters Lite plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'link' attribute of the post_thumbnail (and newsletters_post_thumbnail) shortcodes in versions up to and including 4.15. This is due to insufficient input sanitization and output…

  • CVE-2026-12938MedJul 29, 2026
    risk 0.00cvss 6.4epss 0.00

    The Newsletters Lite plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'target' attribute of the [newsletters_post] shortcode in versions up to and including 4.15. This is due to insufficient input sanitization and output escaping in the posts_single()…

  • CVE-2026-12583HigJul 14, 2026
    risk 0.00cvss 8.1epss 0.01

    The Newsletters WordPress plugin before 4.15 does not prevent deserialization of untrusted input that is stored through a public form, allowing unauthenticated attackers to inject a PHP object and, via a property-oriented gadget chain bundled with the Newsletters WordPress…

  • CVE-2026-57394HigJul 13, 2026
    risk 0.00cvss 7.1epss 0.00

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Tribulant Software Newsletters newsletters-lite allows Reflected XSS.This issue affects Newsletters: from n/a through <= 4.14.

  • CVE-2026-57645HigJun 26, 2026
    risk 0.00cvss 8.1epss 0.00

    newsletters_subscribers Broken Access Control in Newsletters <= 4.13 versions.

  • CVE-2026-54840HigJun 26, 2026
    risk 0.00cvss 7.3epss 0.00

    Unauthenticated Broken Access Control in Newsletters <= 4.13 versions.

Page 2 of 2