PT-2022-13184 · WordPress · Email Subscribers & Newsletters

Krzysztof Zając

·

Published

2022-03-07

·

Updated

2026-02-25

·

CVE-2022-0439

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Email Subscribers & Newsletters WordPress plugin versions prior to 5.3.2
Description The issue concerns a blind SQL injection vulnerability due to incorrect escaping of the order and orderby parameters in the ajax fetch report list action. This can be exploited by users with roles as low as Subscriber. Additionally, the lack of CSRF protection for this action allows attackers to trick logged-in users into performing the action by clicking a link.
Recommendations For versions prior to 5.3.2, update to version 5.3.2 or later to resolve the issue. As a temporary workaround, consider restricting access to the ajax fetch report list action to minimize the risk of exploitation. Avoid using the order and orderby parameters in the affected action until the issue is resolved.

Exploit

Fix

SQL injection

CSRF

Weakness Enumeration

Related Identifiers

CVE-2022-0439

Affected Products

Email Subscribers & Newsletters