WordPress SendPress Newsletters plugin <= 1.23.11.6 - Broken Access Control vulnerability
CVE-2023-35040
9.8CRITICAL
What is CVE-2023-35040?
A missing authorization vulnerability in the SendPress Newsletters plugin may allow unauthorized users to access and manage sensitive information. Affected versions include any version up to 1.23.11.6. This flaw poses a significant risk as it enables potential attackers to manipulate newsletter settings or access sensitive data without proper authentication, compromising the integrity and confidentiality of user information.
Affected Version(s)
SendPress Newsletters <= 1.23.11.6