CVE-2019-14788
15.08.2019, 16:15
wp-admin/admin-ajax.php?action=newsletters_exportmultiple in the Tribulant Newsletters plugin before 4.6.19 for WordPress allows directory traversal with resultant remote PHP code execution via the subscribers[1][1] parameter in conjunction with an exportfile=../ value.
Vendor | Product | Version |
---|---|---|
tribulant | newsletters | 𝑥 < 4.6.19 |
𝑥
= Vulnerable software versions
References