Showing 1 vulnerability on this page for enl_newsletter

Signals CISA KEV Ransomware Nuclei
wordpress vulnerability results
VulnerabilityTitle and contextCVSSEPSSPoCsSignalsSTIX action

ENL Newsletter <= 1.0.1 - Admin+ SQL Injection

The ENL Newsletter WordPress plugin through 1.0.1 does not sanitize and escape a parameter before using it in a SQL statement, allowing admin+ to perform SQL injection attacks

CWE-89Apr 26, 2024
CVSS4.5v3.1EPSS0.512%PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX