CVE-2025-14852 | MDirector Newsletter Plugin up to 4.5.8 on WordPress Setting mdirectorNewsletterSave cross-site request forgery
A vulnerability was found in MDirector Newsletter Plugin up to 4.5.8 on WordPress and classified as problematic. Affected by this vulnerability is the function mdirectorNewsletterSave of the component Setting Handler. The manipulation results in cross-site request forgery.
This vulnerability is reported as CVE-2025-14852. The attack can be launched remotely. No exploit exists.