Known CVE
WordPress Newsletters <= 4.13 - Unauthenticated SQL Injection
Newsletters WordPress plugin <= 4.13 contains a time-based SQL injection caused by insufficient escaping of the 'wpmlsubscriber_id' parameter, letting unauthenticated attackers extract sensitive database information.
CVE-2026-3018
High2026CVSS 7.5CWE-89
cve2026 · sqli · wp · wp-plugin · newsletters-lite · time-based-sqli · vkev
Verified scans run this check after you prove you own the site.
All known CVEsView the checks catalogNational Vulnerability Database
Scan a website