The MailPoet Newsletters plugin for WordPress has a security weakness that allows someone who is not authorized to access it to gain sensitive information from the database. This is possible because of a lack of proper security measures in versions 2.7.2 and earlier. This vulnerability can be exploited by adding additional SQL queries to existing queries.