WordPress Plugin Vulnerabilities

Newsletter Lite < 4.6.19 - Multiple Issues

Description

- Lack of CSRF, Authorisation and sanitisation checks in the ajax_load_new_editor() function, registered as an AJAX method, can lead to an authenticated reflected XSS issue.

- Authenticated Directory Traversal leading to RCE

Proof of Concept

Affects Plugins

Fixed in 4.6.19

References

Miscellaneous

Verified
Yes

Timeline

Publicly Published
2019-07-01 (about 6 years ago)
Added
2019-07-10 (about 6 years ago)
Last Updated
2021-01-13 (about 5 years ago)

Other