Newspack Newsletters, CVE-2024-37475
- CVE, Research URL
- Home page URL
- Application
- Published on
- Nov 01, 2024
- Research Description
- Missing Authorization vulnerability in Automattic Newspack Newsletters allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects Newspack Newsletters: from n/a through 2.13.2.
- Affected versions
-
max 2.13.3.
- Status
-
vulnerable
| Previous vulnerability researches |
|---|
| Newspack Newsletters (CVE-2024-37242) , Jun 24, 2024 |
| Newspack Newsletters (CVE-2024-37475) , Jul 04, 2024 |
| Newspack Newsletters (CVE-2025-49325) , Jun 15, 2025 |