8.8

CVE-2020-35932

Exploit

Newsletter <= 6.8.1 - Authenticated PHP Object Injection

Insecure Deserialization in the Newsletter plugin before 6.8.2 for WordPress allows authenticated remote attackers with minimal privileges (such as subscribers) to use the tpnc_render AJAX action to inject arbitrary PHP objects via the options[inline_edits] parameter. NOTE: exploitability depends on PHP objects that might be present with certain other plugins or themes.
Mögliche Gegenmaßnahme
Newsletter – Send awesome emails from WordPress: Update to version 6.8.2, or a newer patched version
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
TribulantNewsletter SwPlatformwordpress Version < 6.8.2
Weitere Schwachstelleninformationen
SystemWordPress Plugin
Produkt Newsletter – Send awesome emails from WordPress
Version [*, 6.8.2)
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 2.08% 0.791
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 8.8 2.8 5.9
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
nvd@nist.gov 6 6.8 6.4
AV:N/AC:M/Au:S/C:P/I:P/A:P
cve@mitre.org 7.5 1.6 5.9
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
CWE-502 Deserialization of Untrusted Data

The product deserializes untrusted data without sufficiently ensuring that the resulting data will be valid.

https://www.wordfence.com/blog/2020/08/newsletter-plugin-vulnerabilities-affect-over-300000-sites/
Third Party Advisory
Exploit
https://www.wordfence.com/threat-intel/vulnerabilities/id/d684efcd-74fa-4b0c-b8dd-9674a2748fc3
Third Party Advisory