CVE · High

CVE-2020-35932 — Newsletter – Send awesome emails from WordPress [newsletter] < 6.8.2

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2020-35932 Newsletter – Send awesome emails from WordPress [newsletter] < 6.8.2 Deserialization of Untrusted Data High 8.8 < 6.8.2 6.8.2 2020-08-02

CVE-2020-35932

The Newsletter plugin before version 6.8.2 contains an object injection vulnerability in the AJAX handler for 'tnpc_render_callback', which calls the 'restore_options_from_request' function that directly unserializes user-supplied data from the $_POST['options']['inline_edits'] parameter. An attacker with subscriber-level permissions could exploit this by sending a crafted POST request to wp-admin/admin-ajax.php with a malicious serialized object, potentially leveraging magic methods from third-party libraries or other plugins to execute arbitrary code or achieve other critical impacts through a property-oriented programming chain.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.