PHP remote file inclusion vulnerability in confirmUnsubscription.php in NmnNewsletter 1.0.7 allows remote attackers to execute arbitrary PHP code via a URL in the output parameter.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.043
EPSS Ranking 88.5%