CVE-2019-14787: Tribulant Newsletters

Medium severity, CVSS 5.4. EPSS: 1% chance of exploitation in the next 30 days.

The Tribulant Newsletters plugin before 4.6.19 for WordPress allows XSS via the wp-admin/admin-ajax.php?action=newsletters_load_new_editor contentarea parameter.

Affected products

  • Tribulant Newsletters: before 4.6.19 (fixed in 4.6.19)

Published 2019-08-09. Last modified 2026-06-17.