SendPulse Email Marketing Newsletter Sensitive Data Exposure Vulnerability

Vulnerability

A vulnerability allowing the exposure of sensitive system information to an unauthorized control sphere has been identified in the SendPulse Email Marketing Newsletter plugin, specifically in versions through 2.2.1. This issue allows for the retrieval of embedded sensitive data.

Impact

Exploitation of this vulnerability could lead to unauthorized access to sensitive embedded data.

Added: Dec 16, 2025, 9:33 AM
Updated: Dec 16, 2025, 2:42 PM

Vulnerability Rating

Custom Algorithm
spread
5.2
impact
2.5
exploitability
7.6
remediation
0.0
relevance
1.5
threat
0.0
urgency
2.9
incentive
5.8

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.