4.3
CVE-2019-19980
- EPSS 1.02%
- Veröffentlicht 26.12.2019 03:15:11
- Zuletzt bearbeitet 21.11.2024 04:35:46
- Quelle cve@mitre.org
- CVE-Watchlists
- Unerledigt
Email Subscribers & Newsletters <= 4.2.2 - Missing Authorization to Test Email
The WordPress plugin, Email Subscribers & Newsletters, before 4.2.3 had a privilege bypass flaw that allowed authenticated users (Subscriber or greater access) to send test emails from the administrative dashboard on behalf of an administrator. This occurs because the plugin registers a wp_ajax function to send_test_email.
Mögliche Gegenmaßnahme
Email Subscribers & Newsletters – Email Marketing, Post Notifications & Newsletter Plugin for WordPress: Update to version 4.2.3, or a newer patched version
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Icegram ≫ Email Subscribers & Newsletters SwPlatformwordpress Version < 4.2.3
Weitere Schwachstelleninformationen
SystemWordPress Plugin
≫
Produkt
Email Subscribers & Newsletters – Email Marketing, Post Notifications & Newsletter Plugin for WordPress
Version
*-4.2.2
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 1.02% | 0.588 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| nvd@nist.gov | 4.3 | 2.8 | 1.4 |
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
|
| nvd@nist.gov | 4 | 8 | 2.9 |
AV:N/AC:L/Au:S/C:N/I:P/A:N
|
| cve@mitre.org | 4.3 | 2.8 | 1.4 |
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L
|
https://wpvulndb.com/vulnerabilities/9946
https://www.wordfence.com/blog/2019/11/multiple-vulnerabilities-patched-in-email-subscribers-newsletters-plugin/
https://www.wordfence.com/threat-intel/vulnerabilities/id/a04870e0-41c8-464b-b30e-0bf7900e1433