Skip to content

Known CVE

WordPress Newsletters <= 4.13 - Unauthenticated SQL Injection

Newsletters WordPress plugin <= 4.13 contains a time-based SQL injection caused by insufficient escaping of the 'wpmlsubscriber_id' parameter, letting unauthenticated attackers extract sensitive database information.

CVE-2026-3018

High2026CVSS 7.5CWE-89

cve2026 · sqli · wp · wp-plugin · newsletters-lite · time-based-sqli · vkev

Verified scans run this check after you prove you own the site.

All known CVEsView the checks catalogNational Vulnerability Database

Scan a website