cleantalk
Vulnerabilities and Security Researches

Newspack Newsletters, CVE-2024-37475

CVE, Research URL

CVE-2024-37475

Application

Newspack Newsletters

Published on
Nov 01, 2024
Research Description
Missing Authorization vulnerability in Automattic Newspack Newsletters allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects Newspack Newsletters: from n/a through 2.13.2.
Affected versions
Min -, max 2.13.3.
Status
vulnerable