CVE-2025-14904 | anilankola Newsletter Email Subscribe Plugin up to 2.4 on WordPress Setting nels_settings_page cross-site request forgery
A vulnerability has been found in anilankola Newsletter Email Subscribe Plugin up to 2.4 on WordPress and classified as problematic. Affected is the function nels_settings_page of the component Setting Handler. This manipulation causes cross-site request forgery.
This vulnerability is handled as CVE-2025-14904. The attack can be initiated remotely. There is not any exploit available.