The email-newsletter plugin through 20.15 for WordPress has SQL injection.
CVSS 2.0
Severity: HIGH
Problem Type: CWE-89,
Products Affected