WordPress Plugin Vulnerabilities
Newsletter Lite < 4.6.19 - Multiple Issues
Description
- Lack of CSRF, Authorisation and sanitisation checks in the ajax_load_new_editor() function, registered as an AJAX method, can lead to an authenticated reflected XSS issue.
- Authenticated Directory Traversal leading to RCE
Proof of Concept
Affects Plugins
References
CVE
CVE
Miscellaneous
Verified
Yes
WPVDB ID
Timeline
Publicly Published
2019-07-01 (about 6 years ago)
Added
2019-07-10 (about 6 years ago)
Last Updated
2021-01-13 (about 5 years ago)