What the vulnerability does
01Description
Missing Authorization vulnerability in Blossom Themes BlossomThemes Email Newsletter blossomthemes-email-newsletter allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects BlossomThemes Email Newsletter: from n/a through <= 2.2.4.
Explanation of Vulnerability in Simple Terms
02Summary
BlossomThemes Email Newsletter through version 2.2.4 fails to properly check user permissions before allowing access to sensitive functions. A logged-in user with low privileges can read data they should not have access to. Update to a version newer than 2.2.4 to resolve this issue.
What an attacker can do
03Attacker Capabilities
Read sensitive data they should not have access to as a low-privilege user.
Potential impact on your site
04Site Impact
Unauthorized users can access private or restricted information stored by the newsletter plugin.
Conditions required to exploit
05Prerequisites
Attacker must have a low-privilege account on the site (e.g., subscriber or contributor role).
Key dates
06Disclosure timeline
December 9, 2024
CVE published
April 29, 2026
Record updated