7.2
CVSSv3

CVE-2023-4797

Published: 16/01/2024 Updated: 23/01/2024
CVSS v3 Base Score: 7.2 | Impact Score: 5.9 | Exploitability Score: 1.2
VMScore: 0

Vulnerability Summary

The Newsletters WordPress plugin prior to 4.9.3 does not properly escape user-controlled parameters when they are appended to SQL queries and shell commands, which could enable an administrator to run arbitrary commands on the server.

Vulnerable Product Search on Vulmon Subscribe to Product

tribulant newsletters