Impact
The vulnerability is a CSRF flaw in the Tribulant Software Newsletters plugin up to version 4.10. Based on the description, the likely attack vector is a malicious link or embedded form that a logged‑in user unknowingly submits. An attacker can force a logged‑in user to perform unintended actions through a forged request, potentially causing the user to submit or modify newsletter data without awareness.
Affected Systems
Tribulant Software Newsletters plugin, including the Newsletters‑lite component, for all releases from n/a through 4.10 are affected; newer releases are not listed as vulnerable.
Risk and Exploitability
The CVSS score of 4.3 indicates moderate severity, while an EPSS value of less than 1% suggests a low likelihood of exploitation. The vulnerability is not yet listed in the CISA KEV catalog. Based on the description, it is inferred that exploitation requires an authenticated user and a crafted request that the user is tricked into executing, typically by clicking a malicious link or submitting a forged form on another site.
OpenCVE Enrichment
EUVD