SQL Injection Vulnerability in Newsletters Plugin for WordPress
CVE-2026-3018
7.5HIGH
What is CVE-2026-3018?
The Newsletters plugin for WordPress is susceptible to a time-based SQL Injection vulnerability through the 'wpmlsubscriber_id' parameter. This issue arises from insufficient input sanitization and improper handling of SQL queries. As a result, attackers may exploit this vulnerability to inject malicious SQL commands, allowing them to retrieve sensitive information stored in the database without requiring authentication. It is crucial for users of the plugin to upgrade to the latest version to mitigate this risk.
Affected Version(s)
Newsletters 0 <= 4.13