The Newsletter Manager plugin for WordPress is vulnerable to insecure deserialization in versions up to, and including, 1.5.1. This is due to unsanitized input from the 'customFieldsDetails' parameter being passed through a deserialization function. This potentially makes it possible for unauthenticated attackers to inject a serialized PHP object.
History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: Wordfence

Published: 2023-06-07T01:51:47.021Z

Updated: 2024-08-04T17:37:06.864Z

Reserved: 2023-06-06T13:21:59.609Z

Link: CVE-2020-36727

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2023-06-07T02:15:12.673

Modified: 2023-11-07T03:22:30.130

Link: CVE-2020-36727

cve-icon Redhat

No data.