PT-2019-16030 · Icegram · Email Subscribers & Newsletters
Published
2019-12-26
·
Updated
2020-08-24
·
CVE-2019-19980
CVSS v3.1
4.3
Medium
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
Email Subscribers & Newsletters versions prior to 4.2.3
Description
The issue allows authenticated users with Subscriber or greater access to send test emails from the administrative dashboard on behalf of an administrator. This occurs because the plugin registers a wp ajax function to send test emails, specifically the
send test email function.Recommendations
For versions prior to 4.2.3, update to version 4.2.3 or later to resolve the issue. As a temporary workaround, consider restricting access to the administrative dashboard or limiting the privileges of authenticated users to prevent exploitation.
Exploit
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Email Subscribers & Newsletters