Impact
The Newsletters WordPress plugin, versions prior to 4.15, fails to prevent deserialization of untrusted data submitted through a public subscription form. This flaw allows an unauthenticated attacker to inject a crafted PHP object. Combined with a property-oriented gadget chain supplied by the plugin before 4.15, the attacker can write arbitrary files and execute code on the server, leading to full compromise of the site.
Affected Systems
The Newsletters WordPress plugin, versions older than 4.15, is affected. The vulnerability is tied to the public subscription form that accepts custom field values.
Risk and Exploitability
The CVSS base score of 8.1 indicates high severity. The EPSS score of less than 1% suggests that exploitation is rare, and the vulnerability is not listed in the CISA KEV catalog. However, the public subscription form is accessible to anyone on the internet. If an attacker successfully supplies a malicious payload, the gadget chain enables file writes and code execution, allowing full control of the affected WordPress instance.
OpenCVE Enrichment