Newsletters
Newsletters: vulnerabilidades y CVE
Newsletters tiene 15 vulnerabilidades publicadas, 11 de ellas en los últimos 12 meses. 0 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE15
Últimos 12 meses11
Críticas0
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2026-16264 | Media (6.5) | 0.19% | — | 23 sept 2026 | The Newsletters WordPress plugin before 4.18.1 does not perform an ownership check on some of its subscriber management actions, and issues a management session to unauthenticated visitors on request, allowing attackers… |
| CVE-2026-66619 | Alta (7.6) | 0.38% | — | 17 sept 2026 | Administrator SQL Injection in Newsletters <= 4.18 versions. |
| CVE-2026-17522 | Media (5.4) | 0.09% | — | 29 ago 2026 | The Newsletters WordPress plugin before 4.17 does not perform any nonce or capability check when saving one of its settings screens, and writes every submitted parameter into its own options, allowing attackers to make… |
| CVE-2026-17520 | Media (4.8) | 0.12% | — | 29 ago 2026 | The Newsletters WordPress plugin before 4.17 does not generate its API key using a sufficiently random source, deriving it from a publicly known value, allowing unauthenticated attackers to compute the key and perform… |
| CVE-2026-75908 | Media (4.3) | 0.39% | — | 25 ago 2026 | The Newsletters plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 4.17. This is due to the plugin not properly verifying that a user is authorized to perform an action.… |
| CVE-2026-16269 | Media (4.8) | 0.36% | — | 8 ago 2026 | The Newsletters WordPress plugin before 4.16 does not strictly compare its API authentication key, allowing unauthenticated attackers to bypass the API authentication via type juggling and perform privileged actions… |
| CVE-2026-16267 | Alta (8.1) | 0.45% | — | 8 ago 2026 | The Newsletters WordPress plugin before 4.16 does not restrict the classes allowed when unserialising a value taken from a public form submission, allowing unauthenticated attackers to inject arbitrary PHP objects. |
| CVE-2026-16268 | Alta (8.2) | 0.73% | — | 6 ago 2026 | The Newsletters WordPress plugin before 4.16 does not authenticate or validate a bounce-processing request before fetching a user-supplied URL on the server side, allowing unauthenticated attackers to make the site… |
| CVE-2026-12583 | Alta (8.1) | 0.55% | — | 14 jul 2026 | The Newsletters WordPress plugin before 4.15 does not prevent deserialization of untrusted input that is stored through a public form, allowing unauthenticated attackers to inject a PHP object and, via a… |
| CVE-2026-54840 | Alta (7.3) | 0.30% | — | 26 jun 2026 | Unauthenticated Broken Access Control in Newsletters <= 4.13 versions. |
| CVE-2026-3018 | Alta (7.5) | 1.5% | — | 10 jun 2026 | The Newsletters plugin for WordPress is vulnerable to time-based SQL Injection via the ‘wpmlsubscriber_id’ parameter in all versions up to, and including, 4.13 due to insufficient escaping on the user supplied parameter… |
| CVE-2025-3107 | Media (6.5) | 0.41% | — | 13 may 2025 | The Newsletters plugin for WordPress is vulnerable to time-based SQL Injection via the ‘orderby' parameter in all versions up to, and including, 4.9.9.8 due to insufficient escaping on the user supplied parameter and… |
| CVE-2025-2009 | Alta (7.2) | 0.35% | — | 26 mar 2025 | The Newsletters plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the logging functionality in all versions up to, and including, 4.9.9.7 due to insufficient input sanitization and output escaping.… |
| CVE-2024-7411 | Media (5.3) | 0.44% | — | 15 ago 2024 | The Newsletters plugin for WordPress is vulnerable to Full Path Disclosure in all versions up to, and including, 4.9.9. This is due the plugin not preventing direct access to the… |
| CVE-2024-32953 | Alta (7.5) | 0.68% | — | 24 abr 2024 | Insertion of Sensitive Information into Log File vulnerability in Newsletters.This issue affects Newsletters: from n/a through 4.9.5. |
🎯 Cómo se explota (técnicas ATT&CK)
Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.