The Newsletters WordPress plugin before 4.18.1 does not perform an ownership check on some of its subscriber management actions, and issues a management session to unauthenticated visitors on request, allowing attackers to read any subscriber's personal data and overwrite any subscriber's record including their email address.
Get the CyboWatch SIEM platform, hosting, and 24×7 SOC analysts. Call or email us to get started.