CyberRota Analysis
AI-GeneratedAn unauthenticated SQL injection vulnerability exists in the Newsletter Subscription Form, specifically affecting versions 1.5.9 and earlier. This flaw allows attackers to manipulate database queries, potentially leading to unauthorized data access or data compromise. Organizations using affected versions should prioritize immediate remediation to mitigate the risk of exploitation.
CVE
CVE-2026-41555
Severity
CRITICAL
CVSS
9.3
EPSS
N/A
Original NVD Description
Unauthenticated SQL Injection in Newsletter Subscription Form – User Subscriptions Form, Capture Email <= 1.5.9 versions.