Impact
The Newsletter Email Subscribe plugin for WordPress is vulnerable to Cross‑Site Request Forgery in all versions up to 2.4. An error in the nonce validation inside the nels_settings_page function permits an attacker to supply a forged request that changes the plugin’s settings. The primary impact is the ability to alter configuration of the plugin without authentication, which may, based on the description, affect how email notifications are managed and sent.
Affected Systems
WordPress sites that have the Newsletter Email Subscribe plugin version 2.4 or earlier installed from the anilankola vendor are affected.
Risk and Exploitability
The CVSS score of 4.3 indicates moderate severity, and the EPSS score of <1% suggests that active exploitation is currently unlikely. The vulnerability is not listed in CISA KEV. Exploitation requires an attacker to craft a malicious URL and persuade a site administrator to click it, typically through social engineering. Successful exploitation would allow the attacker to modify the plugin’s configuration, potentially changing email behavior and other functionalities controlled by the settings.
OpenCVE Enrichment