CVE-2019-20361
CRITICALIcegram Email Subscribers & Newsletters < 4.3.1 - SQL Injection
Title source: ruleDescription
There was a flaw in the WordPress plugin, Email Subscribers & Newsletters before 4.3.1, that allowed SQL statements to be passed to the database in the hash parameter (a blind SQL injection vulnerability).
Exploits (3)
metasploit
WORKING POC
by h00die, red0xff, Wordfence · rubypoc
https://github.com/rapid7/metasploit-framework/blob/master/modules/auxiliary/scanner/http/wp_email_sub_news_sqli.rb
References (3)
Scores
CVSS v3
9.8
EPSS
0.3109
EPSS Percentile
96.7%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Classification
CWE
CWE-89
Status
published
Affected Products (1)
icegram/email_subscribers_\&_newsletters
< 4.3.1
Timeline
Published
Jan 08, 2020
Tracked Since
Feb 18, 2026