CVE-2024-49621 HIGH

CVE-2024-49621: WordPress APA Register Newsletter Form plugin <= 1.0.0 - CSRF to SQL Injection vulnerability

Vendor Aatmaadhikari
Product APA Register Newsletter Form
Weakness CWE-352 · CSRF
Published October 20, 2024
Last update April 28, 2026

CVSS base score

8.2/10
Attack vector Network
Attack complexity Low
Privileges required None
User interaction Required
Confidentiality High
Integrity None

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:N/A:L

What the vulnerability does

01Description

Cross-Site Request Forgery (CSRF) vulnerability in aatmaadhikari APA Register Newsletter Form apa-register-newsletter-form allows SQL Injection.This issue affects APA Register Newsletter Form: from n/a through <= 1.0.0.

Explanation of Vulnerability in Simple Terms

02Summary

APA Register Newsletter Form versions up to 1.0.0 contain a cross-site request forgery (CSRF) vulnerability. An attacker can craft a malicious webpage that, when visited by a site administrator, performs unwanted actions on the newsletter form without the admin's knowledge. The vulnerability requires user interaction and can affect the confidentiality of data and site availability.

What an attacker can do

03Attacker Capabilities

Trick a site admin into visiting a malicious page that performs unwanted actions on the newsletter form.

Potential impact on your site

04Site Impact

Attackers can modify newsletter settings or data without authorization if an admin visits a malicious link.

Conditions required to exploit

05Prerequisites

Site admin must visit an attacker-controlled webpage while logged into the site.

Key dates

06Disclosure timeline

October 20, 2024 CVE published
April 28, 2026 Record updated

Related vulnerabilities

08Related CVE