CVE-2019-20361
CRITICALIcegram Email Subscribers & Newsletters < 4.3.1 - SQL Injection
Title source: ruleDescription
There was a flaw in the WordPress plugin, Email Subscribers & Newsletters before 4.3.1, that allowed SQL statements to be passed to the database in the hash parameter (a blind SQL injection vulnerability).
Exploits (3)
metasploit
WORKING POC
by h00die, red0xff, Wordfence · rubypoc
https://github.com/rapid7/metasploit-framework/blob/master/modules/auxiliary/scanner/http/wp_email_sub_news_sqli.rb
References (3)
Scores
CVSS v3
9.8
EPSS
0.2812
EPSS Percentile
96.5%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Details
CWE
CWE-89
Status
published
Products (1)
icegram/email_subscribers_\&_newsletters
< 4.3.1
Published
Jan 08, 2020
Tracked Since
Feb 18, 2026