An XSS bug and a PHP object-injection vulnerability are present in a plugin used by hundreds of thousands of websites. Newsletter, a WordPress plugin with more than 300,000 installations, has a pair ...
Newsletter users are urged to update the plugin to the 6.8.3 version as soon as possible to block attacks designed to add rogue admins or to inject backdoors on their sites given that threat actors ...
The flaw could have let attackers send out custom newsletters and delete newsletter subscribers from 200,000 affected websites. Developers of a plugin, used by WordPress websites for building pop-up ...