← WordPress Vulnerabilities
WordPress security by component

Newsletter Manager

Newsletter Manager is a WordPress component with 4 published CVE records in this archive. The latest tracked vulnerability was published Jun 07, 2023; the highest CVE/CNA score is 9.8.

Plugin slug: newsletter-manager

CVE-2020-36727: Newsletter Manager: Code execution

Newsletter Manager is affected by code execution. The vulnerable path is reachable without authentication. Successful exploitation can run attacker-controlled code in the WordPress hosting account.

PublishedJun 07, 2023
Safe version guidanceSee mitigation notes
Safe version
Jun 07, 2023 CVE-2020-36727
Newsletter Manager: Code execution
Newsletter Manager is affected by code execution. The vulnerable path is reachable without authentication. Successful exploitation can run attacker-controlled code in the WordPress hosting account.
See mitigation notes
CVE9.8
NVD9.8
Jan 16, 2014 CVE-2012-6629
Newsletter Manager: Cross-site request forgery
Newsletter Manager is affected by cross-site request forgery. Exposure depends on how the affected operation is made reachable by the site. Exploitation relies on a signed-in privileged user submitting an attacker-controlled request.
See mitigation notes
CVE6.8
NVD6.8
Jan 16, 2014 CVE-2012-6628
Newsletter Manager: Cross-site scripting
Newsletter Manager is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE4.3
NVD4.3
Jan 16, 2014 CVE-2012-6627
Newsletter Manager: Cross-site scripting
Newsletter Manager is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE4.3
NVD4.3