CVE-2025-30921: WordPress Newsletters plugin <= 4.9.9.7 - SQL Injection vulnerability
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Tribulant Software Newsletters newsletters-lite allows SQL Injection.This issue affects Newsletters: from n/a through <= 4.9.9.7.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2025-30921?
CVE-2025-30921 has a high severity rating due to its potential to allow SQL Injection attacks.
How do I fix CVE-2025-30921?
To fix CVE-2025-30921, upgrade the Tribulant Software Newsletters plugin to the latest version above 4.9.9.7.
What impact does CVE-2025-30921 have on my system?
CVE-2025-30921 can allow attackers to execute arbitrary SQL commands, potentially compromising your database.
Which versions are affected by CVE-2025-30921?
CVE-2025-30921 affects Tribulant Software Newsletters versions up to and including 4.9.9.7.
Is my website safe from CVE-2025-30921 if I am using a different version?
If you are using a version of the Tribulant Software Newsletters plugin that is newer than 4.9.9.7, your website is not affected by CVE-2025-30921.