CVE-2020-35932: High severity tribulant software newsletters vulnerability
Insecure Deserialization in the Newsletter plugin before 6.8.2 for WordPress allows authenticated remote attackers with minimal privileges (such as subscribers) to use the tpncrender AJAX action to inject arbitrary PHP objects via the options[inlineedits] parameter. NOTE: exploitability depends on PHP objects that might be present with certain other plugins or themes.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2020-35932?
CVE-2020-35932 is a vulnerability in the Newsletter plugin before version 6.8.2 for WordPress that allows authenticated remote attackers to inject arbitrary PHP objects.
How severe is CVE-2020-35932?
CVE-2020-35932 has a severity score of 8.8 (high).
What software is affected by CVE-2020-35932?
The Newsletter plugin before version 6.8.2 for WordPress is affected by CVE-2020-35932.
How can authenticated remote attackers exploit CVE-2020-35932?
Authenticated remote attackers with minimal privileges, such as subscribers, can exploit CVE-2020-35932 by using the tpnc_render AJAX action to inject arbitrary PHP objects via the options[inline_edits] parameter.
Is there a fix available for CVE-2020-35932?
Yes, updating to version 6.8.2 of the Newsletter plugin for WordPress will fix CVE-2020-35932.