Insecure Deserialization in the Newsletter plugin before 6.8.2 for WordPress allows authenticated remote attackers with minimal privileges (such as subscribers) to use the tpnc_render AJAX action to inject arbitrary PHP objects via the options[inline_edits] parameter. NOTE: exploitability depends on PHP objects that might be present with certain other plugins or themes.
Conclusion & alert: CVE-2020-35932 is rated High Exploit Risk (73.7/100): CVSS High severity, with medium exploitation likelihood (EPSS 2.08%).Core evidence: 1 public exploit reference(s) are indexed (Exploit-DB). EPSS rose +1.08% over the last day, indicating growing attacker interest.Mandatory action: Public exploits are available—assess exposure, apply mitigations, and prioritize patching.
Risk is dynamic; we continuously reassess and refresh what is shown on this page as upstream context changes.
Public exploit references (Exploit-DB) for CVE-2020-35932
Exploit prediction scoring system (EPSS) score for CVE-2020-35932
EPSS lead: Daily EPSS estimates relative likelihood of exploitation; percentile ranks this CVE among scored vulnerabilities (higher = more severe relative rank).