CVE-2023-4797: Tribulant Newsletters
High severity, CVSS 7.2. EPSS: 1% chance of exploitation in the next 30 days.
The Newsletters WordPress plugin before 4.9.3 does not properly escape user-controlled parameters when they are appended to SQL queries and shell commands, which could enable an administrator to run arbitrary commands on the server.
Affected products
- Tribulant Newsletters: before 4.9.3 (fixed in 4.9.3)
Published 2024-01-16. Last modified 2026-06-17.