CVE-2025-30921
CVSS 3.1 Score 7.6 of 10 (high)
Details
Summary
CVE-2025-30921 is a newly disclosed SQL Injection vulnerability affecting Tribulant Software's Newsletters. The flaw, which exists in versions from n/a to 4.9.9.7, stems from improper handling of special elements in SQL commands. An attacker can exploit this vulnerability to inject malicious SQL statements, potentially gaining unauthorized access or manipulating data within the affected system. SQL Injection attacks can lead to significant data breaches and system compromise, making this a critical issue for organizations using Tribulant Software's Newsletters. Users are advised to update to the latest, secure version as soon as possible to mitigate the risk.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Affected Products
- Newsletters Plugin
Affected Vendors
- WordPress