Impact
The vulnerability is a PHP Object Injection flaw that arises from deserializing untrusted data. An attacker could craft malicious serialized objects that, when processed by the plugin, result in the execution of arbitrary PHP code, thereby compromising confidentiality, integrity, and availability of the affected WordPress site.
Affected Systems
Tribulant Software’s Newsletters (Newsletters Lite) plugin is affected when its version is 4.11 or earlier. Any installation of the plugin that has not been updated to a newer release is vulnerable.
Risk and Exploitability
The CVSS score of 9.8 reflects a critical risk. Although the EPSS score indicates a very low probability of exploitation, the vulnerability is not listed in CISA’s KEV catalog, suggesting that no widespread exploitation is known yet. The attack vector is inferred to rely on untrusted user input that is deserialized by the plugin; an attacker can therefore execute arbitrary code if the plugin is actively processing data from an external source.
OpenCVE Enrichment