CVE-2018-20987: Critical severity tribulant software newsletters vulnerability
Published Aug 22, 2019
·Updated
The newsletters-lite plugin before 4.6.8.6 for WordPress has PHP object injection.
Affected Software
1 affected component
Tribulant Newsletters Wordpress<4.6.8.6
Event History
Aug 22, 2019
CVE Published
via MITRE·07:04 PM
Data Sourced
via MITRE·07:04 PM
Description
Frequently Asked Questions
1
What is the vulnerability ID of this vulnerability?
The vulnerability ID is CVE-2018-20987.
2
What is the severity level of CVE-2018-20987?
The severity level of CVE-2018-20987 is critical (9.8).
3
What is the affected software by CVE-2018-20987?
The affected software is the newsletters-lite plugin before version 4.6.8.6 for WordPress.
4
What is the vulnerability description for CVE-2018-20987?
CVE-2018-20987 is a PHP object injection vulnerability in the newsletters-lite plugin before version 4.6.8.6 for WordPress.
5
How can I fix the PHP object injection vulnerability in newsletters-lite plugin?
To fix the PHP object injection vulnerability in newsletters-lite plugin, update to version 4.6.8.6 or later.