Vulnerabilities
Vulnerable Software
Tribulant:  >> Newsletter  >> 3.8.5  Security Vulnerabilities
Insecure Deserialization in the Newsletter plugin before 6.8.2 for WordPress allows authenticated remote attackers with minimal privileges (such as subscribers) to use the tpnc_render AJAX action to inject arbitrary PHP objects via the options[inline_edits] parameter. NOTE: exploitability depends on PHP objects that might be present with certain other plugins or themes.
CVSS Score
7.5
EPSS Score
0.01
Published
2021-01-01


Contact Us

Shodan ® - All rights reserved