SQL injection (SQLi) vulnerability found by Erik David Martin in WordPress Newsletter by Supsystic plugin (versions <= 1.5.6).
Solution
2021-02-08 - we were unable to find a patched version of this plugin.
WordPress plugin repository notice: "This plugin has been closed as of December 1, 2020 and is not available for download. Reason: Security Issue."