First published: Thu Aug 22 2019(Updated: )
The newsletters-lite plugin before 4.6.8.6 for WordPress has PHP object injection.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Tribulant Newsletters | <4.6.8.6 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID is CVE-2018-20987.
The severity level of CVE-2018-20987 is critical (9.8).
The affected software is the newsletters-lite plugin before version 4.6.8.6 for WordPress.
CVE-2018-20987 is a PHP object injection vulnerability in the newsletters-lite plugin before version 4.6.8.6 for WordPress.
To fix the PHP object injection vulnerability in newsletters-lite plugin, update to version 4.6.8.6 or later.