Impact
The Newsletters plugin for WordPress versions 4.18 and earlier contains an SQL Injection flaw that can be triggered by a user with administrator privileges. The vulnerability allows the injection of arbitrary SQL code into the plugin’s database operations, potentially giving the attacker the ability to read or alter data stored by the plugin. No explicit statement of the exact data accessed is provided in the CVE, so the maximum impact is limited to queries permitted by the database user associated with the plugin.
Affected Systems
Tribulant Software’s WordPress Newsletters plugin, all releases version 4.18 and earlier, are susceptible to this flaw. Administrators who maintain WordPress sites using these plugin versions are at risk until the plugin is updated to 4.18.1 or later.
Risk and Exploitability
The assigned CVSS score of 7.6 indicates high severity. EPSS data is unavailable and the vulnerability is not listed as a CISA KEV, suggesting it has not yet been widely exploited. Because the exploit requires authenticated administrator access, the attack vector is limited to users who can log into the WordPress backend. The lack of public exploitation metrics means the immediate exposure is reduced, but any administrative account that could log into the site remains a potential attacker pathway.
OpenCVE Enrichment