The newsletters-lite plugin before 4.6.8.6 for WordPress has PHP object injection.
The product deserializes untrusted data without sufficiently ensuring that the resulting data will be valid.
Link | Tags |
---|---|
https://wordpress.org/plugins/newsletters-lite/#developers | release notes |
https://wpvulndb.com/vulnerabilities/9627 | third party advisory |