CVE-2019-19985
icegram email_subscribers_\&_newsletters Missing Authorization
Record summary
CVE-2019-19985 has a selected CVSS score of 5.3 (medium); EIP currently links 1 catalogued exploit and 1 Nuclei template.
Description
The WordPress plugin, Email Subscribers & Newsletters, before 4.2.3 had a flaw that allowed unauthenticated file download with user information disclosure.
Exploitation context
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
email_subscribers_\&_newslettersBrowse icegram / email_subscribers_\&_newsletters | VulnCheck | Version data not supplied | |
Proofs of concept
1Catalogued exploits
ExploitDBWordPress Plugin Email Subscribers & Newsletters 4.2.2 - Unauthenticated File DownloadExploitDB exploitby KBA@SOGETI_ESECNot analyzed1 file
Nuclei templates
1ProjectDiscoveryMEDIUMWordPress Email Subscribers & Newsletters <4.2.3 - Arbitrary File RetrievalCVSS 5.3
WordPress Email Subscribers & Newsletters plugin before 4.2.3 is susceptible to arbitrary file retrieval via a flaw that allows unauthenticated file download and user information disclosure. An attacker can obtain sensitive information, modify data, and/or execute unauthorized administrative operations.
Impact
An attacker can access sensitive files on the server, potentially leading to unauthorized access or data leakage.
Remediation
Update to the latest version of WordPress Email Subscribers & Newsletters plugin (4.2.3) or apply the patch provided by the vendor.
Source: ProjectDiscovery