The Newsletter Manager plugin for WordPress is vulnerable to insecure deserialization in versions up to, and including, 1.5.1. This is due to unsanitized input from the 'customFieldsDetails' parameter being passed through a deserialization function. This potentially makes it possible for unauthenticated attackers to inject a serialized PHP object.
References
Configurations
History
13 Jun 2023, 13:38
Type | Values Removed | Values Added |
---|---|---|
CPE | cpe:2.3:a:xyzscripts:newsletter_manager:*:*:-:*:-:wordpress:*:* | |
CVSS |
v2 : v3 : |
v2 : unknown
v3 : 9.8 |
References | (MISC) https://wpscan.com/vulnerability/b82124b1-e5e1-4f1e-9513-90474fd3f066 - Third Party Advisory | |
References | (MISC) https://blog.nintechnet.com/insecure-deserialization-vulnerability-in-wordpress-newsletter-manager-plugin-unpatched/ - Exploit | |
References | (MISC) https://www.wordfence.com/threat-intel/vulnerabilities/id/dcfd8c4d-d48b-468d-a7d5-1ec05b068f79?source=cve - Third Party Advisory | |
CWE | CWE-502 |
07 Jun 2023, 02:44
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2023-06-07 02:15
Updated : 2024-02-04 23:37
NVD link : CVE-2020-36727
Mitre link : CVE-2020-36727
CVE.ORG link : CVE-2020-36727
JSON object : View
Products Affected
xyzscripts
- newsletter_manager
CWE
CWE-502
Deserialization of Untrusted Data