Record summary

CVE-2019-19985 has a selected CVSS score of 5.3 (medium); EIP currently links 1 catalogued exploit and 1 Nuclei template.

Description

The WordPress plugin, Email Subscribers & Newsletters, before 4.2.3 had a flaw that allowed unauthenticated file download with user information disclosure.

Description source: CVE List

Exploitation context

Known exploitation

VulnCheck KEV
Listed · Nov 13, 2019 · VulnCheck
Reported exploitation
Observed · VulnCheck

Available material

Catalogued exploits
1
Nuclei templates
1

Affected products and versions

1
ProductSourceVersion rangeStatus
VulnCheckVersion data not supplied

Proofs of concept

1

Catalogued exploits

ExploitDBWordPress Plugin Email Subscribers & Newsletters 4.2.2 - Unauthenticated File DownloadExploitDB exploitby KBA@SOGETI_ESECNot analyzed1 file
ExploitDB

PoC details

Nuclei templates

1
ProjectDiscoveryMEDIUMWordPress Email Subscribers & Newsletters <4.2.3 - Arbitrary File RetrievalCVSS 5.3

WordPress Email Subscribers & Newsletters plugin before 4.2.3 is susceptible to arbitrary file retrieval via a flaw that allows unauthenticated file download and user information disclosure. An attacker can obtain sensitive information, modify data, and/or execute unauthorized administrative operations.

Impact

An attacker can access sensitive files on the server, potentially leading to unauthorized access or data leakage.

Remediation

Update to the latest version of WordPress Email Subscribers & Newsletters plugin (4.2.3) or apply the patch provided by the vendor.

WeaknessesCWE-862
AuthorsKBA@SOGETI_ESEC, madrobot, dwisiswant0
Template tagscvecve2019wordpresswp-pluginedbpacketstormicegramvkevvuln
CVSS vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
CPE: cpe:2.3:a:icegram:email_subscribers_\&_newsletters:*:*:*:*:*:wordpress:*:*

Source: ProjectDiscovery

References

4