CVE-2026-66619: WordPress Newsletters plugin <= 4.18 - SQL Injection vulnerability
Published Sep 17, 2026
·Updated
Administrator SQL Injection in Newsletters <= 4.18 versions.
Affected Software
1 affected component
WordPress Newsletters<=4.18
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
WordPress Newsletters pluginto a version that resolves this vulnerability.Fixed in 4.18.1
Event History
Sep 17, 2026
CVE Published
via MITRE·01:24 PM
Data Sourced
via MITRE·01:24 PM
RemedyDescriptionSeverityWeakness
Frequently Asked Questions
1
What level of access does an attacker need?
An attacker needs administrator privileges to exploit this issue. The vulnerability is therefore most relevant where administrator accounts are compromised, shared, or improperly granted.
2
Is the issue remotely exploitable?
The CVSS vector indicates network-based exploitation with low attack complexity and no user interaction required. However, exploitation still requires high privileges.
3
What security impact could successful exploitation have?
Successful exploitation can result in high confidentiality impact and low availability impact. The integrity impact is listed as none, while the scope is changed.