The Newsletter Manager plugin for WordPress is vulnerable to insecure deserialization in versions up to, and including, 1.5.1. This is due to unsanitized input from the 'customFieldsDetails' parameter being passed through a deserialization function. This potentially makes it possible for unauthenticated attackers to inject a serialized PHP object.
References
Configurations
History
No history.
Information
Published : 2023-06-07 02:15
Updated : 2023-11-07 03:22
NVD link : CVE-2020-36727
Mitre link : CVE-2020-36727
CVE.ORG link : CVE-2020-36727
JSON object : View
Products Affected
xyzscripts
- newsletter_manager
CWE
CWE-502
Deserialization of Untrusted Data