Security Advisory

CVE-2023-4797

CVE vulnerability detail — eXtreme Datacenter Security Operations

Published 2024-01-16 15:56:40
Last updated 2025-06-11 16:43:37
Assigner WPScan
State PUBLISHED

Description

The Newsletters WordPress plugin before 4.9.3 does not properly escape user-controlled parameters when they are appended to SQL queries and shell commands, which could enable an administrator to run arbitrary commands on the server.