SQL injection vulnerability in shiftthis-preview.php in the ShiftThis Newsletter (st_newsletter) plugin for WordPress allows remote attackers to execute arbitrary SQL commands via the newsletter parameter.Referenceshttps://www.exploit-db.com/exploits/5053http://www.securityfocus.com/bid/27586