Newsletters Lite
by WordPress
Source repositories
CVEs (30)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2026-16269 | Med | 0.31 | 4.8 | 0.00 | Aug 8, 2026 | The Newsletters WordPress plugin before 4.16 does not strictly compare its API authentication key, allowing unauthenticated attackers to bypass the API authentication via type juggling and perform privileged actions such as modifying subscriber records and sending emails, when… | ||
| CVE-2025-54035 | Med | 0.28 | 4.3 | 0.00 | Jul 16, 2025 | Cross-Site Request Forgery (CSRF) vulnerability in Tribulant Software Newsletters newsletters-lite allows Cross Site Request Forgery.This issue affects Newsletters: from n/a through <= 4.10. | ||
| CVE-2024-37227 | Med | 0.28 | 4.3 | 0.00 | Jun 21, 2024 | Cross Site Request Forgery (CSRF) vulnerability in Tribulant Newsletters.This issue affects Newsletters: from n/a through 4.9.7. | ||
| CVE-2024-7411 | Med | 0.27 | 5.3 | 0.00 | Aug 15, 2024 | The Newsletters plugin for WordPress is vulnerable to Full Path Disclosure in all versions up to, and including, 4.9.9. This is due the plugin not preventing direct access to the /vendor/mobiledetect/mobiledetectlib/export/exportToJSON.php. This makes it possible for… | ||
| CVE-2026-12939 | Med | 0.00 | 6.4 | 0.00 | Jul 29, 2026 | The Newsletters Lite plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'link' attribute of the post_thumbnail (and newsletters_post_thumbnail) shortcodes in versions up to and including 4.15. This is due to insufficient input sanitization and output… | ||
| CVE-2026-12938 | Med | 0.00 | 6.4 | 0.00 | Jul 29, 2026 | The Newsletters Lite plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'target' attribute of the [newsletters_post] shortcode in versions up to and including 4.15. This is due to insufficient input sanitization and output escaping in the posts_single()… | ||
| CVE-2026-12583 | Hig | 0.00 | 8.1 | 0.00 | Jul 14, 2026 | The Newsletters WordPress plugin before 4.15 does not prevent deserialization of untrusted input that is stored through a public form, allowing unauthenticated attackers to inject a PHP object and, via a property-oriented gadget chain bundled with the Newsletters WordPress… | ||
| CVE-2026-57394 | Hig | 0.00 | 7.1 | 0.00 | Jul 13, 2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Tribulant Software Newsletters newsletters-lite allows Reflected XSS.This issue affects Newsletters: from n/a through <= 4.14. | ||
| CVE-2026-57645 | Hig | 0.00 | 8.1 | 0.00 | Jun 26, 2026 | newsletters_subscribers Broken Access Control in Newsletters <= 4.13 versions. | ||
| CVE-2026-54840 | Hig | 0.00 | 7.3 | 0.00 | Jun 26, 2026 | Unauthenticated Broken Access Control in Newsletters <= 4.13 versions. |
- risk 0.31cvss 4.8epss 0.00
The Newsletters WordPress plugin before 4.16 does not strictly compare its API authentication key, allowing unauthenticated attackers to bypass the API authentication via type juggling and perform privileged actions such as modifying subscriber records and sending emails, when…
- risk 0.28cvss 4.3epss 0.00
Cross-Site Request Forgery (CSRF) vulnerability in Tribulant Software Newsletters newsletters-lite allows Cross Site Request Forgery.This issue affects Newsletters: from n/a through <= 4.10.
- risk 0.28cvss 4.3epss 0.00
Cross Site Request Forgery (CSRF) vulnerability in Tribulant Newsletters.This issue affects Newsletters: from n/a through 4.9.7.
- risk 0.27cvss 5.3epss 0.00
The Newsletters plugin for WordPress is vulnerable to Full Path Disclosure in all versions up to, and including, 4.9.9. This is due the plugin not preventing direct access to the /vendor/mobiledetect/mobiledetectlib/export/exportToJSON.php. This makes it possible for…
- risk 0.00cvss 6.4epss 0.00
The Newsletters Lite plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'link' attribute of the post_thumbnail (and newsletters_post_thumbnail) shortcodes in versions up to and including 4.15. This is due to insufficient input sanitization and output…
- risk 0.00cvss 6.4epss 0.00
The Newsletters Lite plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'target' attribute of the [newsletters_post] shortcode in versions up to and including 4.15. This is due to insufficient input sanitization and output escaping in the posts_single()…
- risk 0.00cvss 8.1epss 0.00
The Newsletters WordPress plugin before 4.15 does not prevent deserialization of untrusted input that is stored through a public form, allowing unauthenticated attackers to inject a PHP object and, via a property-oriented gadget chain bundled with the Newsletters WordPress…
- risk 0.00cvss 7.1epss 0.00
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Tribulant Software Newsletters newsletters-lite allows Reflected XSS.This issue affects Newsletters: from n/a through <= 4.14.
- risk 0.00cvss 8.1epss 0.00
newsletters_subscribers Broken Access Control in Newsletters <= 4.13 versions.
- risk 0.00cvss 7.3epss 0.00
Unauthenticated Broken Access Control in Newsletters <= 4.13 versions.
Page 2 of 2