Impact
The vulnerability is an unauthenticated broken access control flaw in the WordPress Newsletters plugin versions up to 4.13. It allows an attacker to manipulate or potentially read newsletter content without needing valid user credentials. This can lead to unauthorized configuration changes, accidental data exposure, or manipulation of published newsletters.
Affected Systems
The flaw affects WordPress installations that use the Tribulant Software Newsletters plugin version 4.13 or earlier. The issue is limited to this plugin and does not extend to other WordPress core components or unrelated plugins.
Risk and Exploitability
The CVSS score of 7.3 indicates a high severity. EPSS data is not available, so the exact exploitation probability is unknown. The vulnerability is not listed in the CISA KEV catalog. Attackers can exploit the flaw remotely by making unauthenticated HTTP requests to protected newsletter management endpoints, potentially gaining full control over the newsletter configuration if access controls are bypassed. The likely vector is a direct web request; the vulnerability is trivial to reach for any user with network access to the WordPress site.
OpenCVE Enrichment