CVE-2023-4797: Tribulant Newsletters

High severity, CVSS 7.2. EPSS: 1% chance of exploitation in the next 30 days.

The Newsletters WordPress plugin before 4.9.3 does not properly escape user-controlled parameters when they are appended to SQL queries and shell commands, which could enable an administrator to run arbitrary commands on the server.

Affected products

  • Tribulant Newsletters: before 4.9.3 (fixed in 4.9.3)

Published 2024-01-16. Last modified 2026-06-17.