Description
Administrator SQL Injection in Newsletters <= 4.18 versions.
Published: 2026-09-17
Score: 7.6 High
EPSS: < 1% Very Low
KEV: No
Impact: SQL Injection with Administrative Access
Action: Immediate Patch
AI Analysis

Impact

The Newsletters plugin for WordPress versions 4.18 and earlier contains an SQL Injection flaw that can be triggered by a user with administrator privileges. The vulnerability allows the injection of arbitrary SQL code into the plugin’s database operations, potentially giving the attacker the ability to read or alter data stored by the plugin. No explicit statement of the exact data accessed is provided in the CVE, so the maximum impact is limited to queries permitted by the database user associated with the plugin.

Affected Systems

Tribulant Software’s WordPress Newsletters plugin, all releases version 4.18 and earlier, are susceptible to this flaw. Administrators who maintain WordPress sites using these plugin versions are at risk until the plugin is updated to 4.18.1 or later.

Risk and Exploitability

The assigned CVSS score of 7.6 indicates high severity. EPSS data is unavailable and the vulnerability is not listed as a CISA KEV, suggesting it has not yet been widely exploited. Because the exploit requires authenticated administrator access, the attack vector is limited to users who can log into the WordPress backend. The lack of public exploitation metrics means the immediate exposure is reduced, but any administrative account that could log into the site remains a potential attacker pathway.

Generated by OpenCVE AI on September 17, 2026 at 22:28 UTC.

Remediation

Vendor Solution

Update the WordPress Newsletters Plugin to the latest available version (at least 4.18.1).


OpenCVE Recommended Actions

  • Upgrade the WordPress Newsletters plugin to version 4.18.1 or newer.
  • Restrict administrative access to essential personnel and monitor login activity for the plugin’s area.
  • Review and, if necessary, adjust database permissions for the plugin to limit the scope of any SQL commands that could be run.

Generated by OpenCVE AI on September 17, 2026 at 22:28 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 29 Sep 2026 13:30:00 +0000

Type Values Removed Values Added
First Time appeared Tribulant
Tribulant newsletters
Wordpress-extensions
Wordpress-extensions newsletters
Vendors & Products Tribulant
Tribulant newsletters
Wordpress-extensions
Wordpress-extensions newsletters

Sat, 19 Sep 2026 03:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 17 Sep 2026 13:30:00 +0000

Type Values Removed Values Added
Description Administrator SQL Injection in Newsletters <= 4.18 versions.
Title WordPress Newsletters plugin <= 4.18 - SQL Injection vulnerability
Weaknesses CWE-89
References
Metrics cvssV3_1

{'score': 7.6, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:N/A:L'}


Subscriptions

Tribulant Newsletters
Wordpress-extensions Newsletters
cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-09-19T02:22:48.512Z

Reserved: 2026-07-27T14:00:21.730Z

Link: CVE-2026-66619

cve-icon Vulnrichment

Updated: 2026-09-19T02:22:43.774Z

cve-icon NVD

Status : Deferred

Published: 2026-09-17T14:17:17.893

Modified: 2026-09-19T03:17:15.060

Link: CVE-2026-66619

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-29T13:22:36Z

Weaknesses
  • CWE-89

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')