VendorsTribulantnewslettersall versions
Vulnerabilities

Tribulant Newsletters

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

11CVEs
CVE-2018-20987
The newsletters-lite plugin before 4.6.8.6 for WordPress has PHP object injection.
Published 2019-08-22 · Modified
9.8EPSS 0.021
CVE-2019-14788
wp-admin/admin-ajax.php?action=newsletters_exportmultiple in the Tribulant Newsletters plugin before 4.6.19 for WordPress allows directory traversal with resultant remote PHP code execution via the subscribers[1][1] parameter in conjunction with an exportfile=../ value.
Published 2019-08-15 · Modified
8.8EPSS 0.037
CVE-2024-8247
Newsletters <= 4.9.9.2 - Authenticated Privilege Escalation
Published 2024-09-06 · Analyzed
8.8EPSS 0.005
CVE-2023-30478
WordPress Newsletters Plugin <= 4.8.8 is vulnerable to Cross Site Request Forgery (CSRF)
Published 2023-11-10 · Modified
8.8EPSS 0.003
CVE-2024-37227
WordPress Newsletters plugin <= 4.9.7 - Cross Site Request Forgery (CSRF) vulnerability
Published 2024-06-21 · Modified
8.8EPSS 0.002
CVE-2023-4797
Newsletter Lite < 4.9.3 - Admin+ Command Injection
Published 2024-01-16 · Modified
7.2EPSS 0.010
CVE-2025-4857
Newsletters <= 4.9.9.9 - Authenticated (Administrator+) Local File Inclusion
Published 2025-05-31 · Analyzed
7.2EPSS 0.008
CVE-2024-35718
WordPress Newsletters plugin <= 4.9.5 - Reflected Cross Site Scripting (XSS) vulnerability
Published 2024-06-08 · Modified
7.1EPSS 0.003
CVE-2024-10181
Newsletters <= 4.9.9.4 - Authenticated (Contributor+) Stored Cross-Site Scripting via newsletters_video Shortcode
Published 2024-10-29 · Analyzed
6.4EPSS 0.004
CVE-2024-13739
Newsletters <= 4.9.9.7 - Reflected Cross-Site Scripting via To Parameter
Published 2025-03-22 · Analyzed
6.1EPSS 0.003
CVE-2019-14787
The Tribulant Newsletters plugin before 4.6.19 for WordPress allows XSS via the wp-admin/admin-ajax.php?action=newsletters_load_new_editor contentarea parameter.
Published 2019-08-09 · Modified
5.4EPSS 0.010