Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

Newsletters — Vulnerabilities & Security Advisories 36

All 36 CVE vulnerabilities found in Newsletters, with AI-generated Chinese analysis, references, and POCs.

This page aggregates vulnerability data for the product Newsletters, mapping specific security weaknesses to the relevant vendor and product categories. The collection encompasses a wide range of defect types, including buffer overflows, input validation errors, and privilege escalation issues, covering advisory records from 2005 through the present day. Readers can use this resource to track a vendor’s published security advisories, understand the impact of a particular weakness class, and review the complete vulnerability history associated with this product line. The interface allows filtering by weakness type, severity, and disclosure date, enabling precise analysis of historical and current security risks.

Vendor: Tribulant

CVE ID Title CVSS Severity Published
CVE-2026-16264 Newsletters < 4.18.1 - Unauthenticated Subscriber Record Overwrite and PII Disclosure via IDOR - - 2026-09-23
CVE-2026-66619 WordPress Newsletters plugin <= 4.18 - SQL Injection vulnerability CWE-89 7.6 High 2026-09-17
CVE-2026-17520 Newsletters < 4.17 - Unauthenticated API Access via Predictable API Key - - 2026-08-29
CVE-2026-17522 Newsletters < 4.17 - Arbitrary Plugin Option Update via CSRF - - 2026-08-29
CVE-2026-75908 Newsletters <= 4.17 - Missing Authorization to Authenticated (Author+) Arbitrary Modification via 'newsletters_mailinglistsroles' POST Parameter CWE-862 4.3 Medium 2026-08-25
CVE-2026-16267 Newsletters < 4.16 - Unauthenticated PHP Object Injection via Date Form Field - - 2026-08-08
CVE-2026-16269 Newsletters < 4.16 - Unauthenticated API Authentication Bypass via Type Juggling - - 2026-08-08
CVE-2026-16268 Newsletters < 4.16 - Unauthenticated Server-Side Request Forgery via SNS Bounce Handler - - 2026-08-06
CVE-2026-12938 Newsletters <= 4.15 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'target' Shortcode Attribute CWE-79 6.4 Medium 2026-07-29
CVE-2026-12939 Newsletters <= 4.15 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'link' Shortcode Attribute CWE-79 6.4 Medium 2026-07-29
CVE-2026-12583 Newsletters < 4.15 - Unauthenticated PHP Object Injection via Subscriber Custom Field - - 2026-07-14
CVE-2026-57394 WordPress Newsletters plugin <= 4.14 - Cross Site Scripting (XSS) vulnerability CWE-79 7.1 High 2026-07-13
CVE-2026-57645 WordPress Newsletters plugin <= 4.13 - Broken Access Control vulnerability CWE-862 8.1 High 2026-06-26
CVE-2026-54840 WordPress Newsletters plugin <= 4.13 - Broken Access Control vulnerability CWE-862 7.3 High 2026-06-26
CVE-2026-3018 Newsletters <= 4.13 - Unauthenticated SQL Injection via wpmlsubscriber_id Parameter CWE-89 7.5 High 2026-06-10
CVE-2025-67911 WordPress Newsletters plugin <= 4.11 - PHP Object Injection vulnerability CWE-502 9.8 Critical 2026-01-08
CVE-2025-69020 WordPress Newsletters plugin <= 4.12 - Cross Site Scripting (XSS) vulnerability CWE-79 6.5 Medium 2025-12-30
CVE-2025-54034 WordPress Newsletters plugin <= 4.10 - Local File Inclusion vulnerability CWE-98 7.5 High 2025-08-20
CVE-2025-54035 WordPress Newsletters plugin <= 4.10 - Cross Site Request Forgery (CSRF) Vulnerability CWE-352 4.3 Medium 2025-07-16
CVE-2025-4857 Newsletters <= 4.9.9.9 - Authenticated (Administrator+) Local File Inclusion CWE-22 7.2 High 2025-05-31
CVE-2025-3107 Newsletters <= 4.9.9.8 - Authenticated (Contributor+) SQL Injection orderby Parameter CWE-89 6.5 Medium 2025-05-13
CVE-2025-30921 WordPress Newsletters plugin <= 4.9.9.7 - SQL Injection vulnerability CWE-89 7.6 High 2025-03-27
CVE-2025-2009 Newsletters <= 4.9.9.7 - Unauthenticated Stored Cross-Site Scripting CWE-79 7.2 High 2025-03-26
CVE-2024-13739 Newsletters <= 4.9.9.7 - Reflected Cross-Site Scripting via To Parameter CWE-79 6.1 Medium 2025-03-22
CVE-2025-24599 WordPress Newsletters plugin <= 4.9.9.6 - Reflected Cross Site Scripting (XSS) vulnerability CWE-79 7.1 High 2025-02-04
CVE-2024-10181 Newsletters <= 4.9.9.4 - Authenticated (Contributor+) Stored Cross-Site Scripting via newsletters_video Shortcode CWE-79 6.4 Medium 2024-10-29
CVE-2024-47346 WordPress Newsletters plugin <= 4.9.9.1 - Reflected Cross Site Scripting (XSS) vulnerability CWE-79 7.1 High 2024-10-06
CVE-2024-8247 Newsletters <= 4.9.9.2 - Authenticated Privilege Escalation CWE-269 8.8 High 2024-09-06
CVE-2024-43279 WordPress Newsletters plugin <= 4.9.8 - Cross Site Scripting (XSS) vulnerability CWE-79 7.1 High 2024-08-18
CVE-2024-7411 Newsletters <= 4.9.9 - Unauthenticated Full Path Disclosure CWE-200 5.3 Medium 2024-08-15

All 36 known CVE vulnerabilities affecting Newsletters with full Chinese analysis, references, and POCs where available.