PT-2019-16030 · Icegram · Email Subscribers & Newsletters

Publicado

2019-12-26

·

Atualizado

2020-08-24

·

CVE-2019-19980

CVSS v3.1

4.3

Média

VetorAV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
Name of the Vulnerable Software and Affected Versions Email Subscribers & Newsletters versions prior to 4.2.3
Description The issue allows authenticated users with Subscriber or greater access to send test emails from the administrative dashboard on behalf of an administrator. This occurs because the plugin registers a wp ajax function to send test emails, specifically the send test email function.
Recommendations For versions prior to 4.2.3, update to version 4.2.3 or later to resolve the issue. As a temporary workaround, consider restricting access to the administrative dashboard or limiting the privileges of authenticated users to prevent exploitation.

Exploit

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Identificadores relacionados

CVE-2019-19980

Produtos afetados

Email Subscribers & Newsletters