CVE-2024-37227 MEDIUM

CVE-2024-37227: WordPress Newsletters plugin <= 4.9.7 - Cross Site Request Forgery (CSRF) vulnerability

Vendor Tribulant
Product Newsletters
Published June 21, 2024
Last update April 28, 2026

CVSS base score

4.3/10
Attack vector Network
Attack complexity Low
Privileges required None
User interaction Required
Confidentiality None
Integrity Low

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N

What the vulnerability does

01Description

Cross Site Request Forgery (CSRF) vulnerability in Tribulant Newsletters.This issue affects Newsletters: from n/a through 4.9.7.

Explanation of Vulnerability in Simple Terms

02Summary

Tribulant Newsletters versions up to 4.9.7 contain an input validation flaw that allows attackers to inject malicious content into the application. An attacker must trick a user into visiting a crafted link or page to exploit this vulnerability. The injected content can modify how the site displays information to that user, but cannot steal data or crash the site.

What an attacker can do

03Attacker Capabilities

Inject malicious content that alters how the site displays to a victim who clicks a malicious link.

Potential impact on your site

04Site Impact

Users visiting attacker-controlled links may see altered site content; no data breach or site outage risk.

Conditions required to exploit

05Prerequisites

Attacker must trick a user into clicking a link or visiting a page containing the malicious payload.

Key dates

06Disclosure timeline

June 21, 2024 CVE published
April 28, 2026 Record updated