Impact
The Newsletters plugin for WordPress contains a time‑based SQL injection flaw through the unchecked ‘orderby’ parameter. This weakness is CWE‑89 and permits authenticated attackers with Contributor‑level or higher permissions to inject and execute arbitrary SQL clauses in existing queries. Successful exploitation enables the attacker to read privileged database data, potentially exposing user credentials, email lists and other sensitive information. The likely attack vector is via the plugin’s shortcode URL where the orderby value is passed by an authenticated user.
Affected Systems
The affected product is the Newsletters plugin for WordPress, a contrib plugin, in all releases up to and including version 4.9.9.8.
Risk and Exploitability
The CVSS score of 6.5 indicates moderate severity. Combined with an EPSS score of less than 1 % and the fact that the flaw is not listed in the CISA KEV catalog, the current external exploitation risk is low, but vulnerable installations remain at risk if an attacker gains Contributor‑level access. The exploitation requires web‑based interaction with the plugin’s shortcode and authenticated access, making it less likely to be leveraged by random attackers but still a meaningful threat to sites with such user roles.
OpenCVE Enrichment
EUVD