The Newsletter Manager plugin for WordPress is vulnerable to insecure deserialization in versions up to, and including, 1.5.1. This is due to unsanitized input from the 'customFieldsDetails' parameter being passed through a deserialization function. This potentially makes it possible for unauthenticated attackers to inject a serialized PHP object.
Metrics
Affected Vendors & Products
References
History
Sat, 28 Dec 2024 01:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|

Status: PUBLISHED
Assigner: Wordfence
Published:
Updated: 2024-12-28T00:53:07.212Z
Reserved: 2023-06-06T13:21:59.609Z
Link: CVE-2020-36727

Updated: 2024-08-04T17:37:06.864Z

Status : Modified
Published: 2023-06-07T02:15:12.673
Modified: 2024-11-21T05:30:10.430
Link: CVE-2020-36727

No data.