Drupal Simplenews Scheduler third party module version 6.x suffers from an arbitrary PHP code execution vulnerability.