Icegram Express – Email Marketing, Newsletters and Automation for WordPress & WooCommerce, CVE-2019-14364
- CVE, Research URL
- Home page URL
- Application
-
Icegram Express – Email Marketing, Newsletters and Automation for WordPress & WooCommerce
- Published on
- Jul 28, 2019
- Research Description
- An XSS vulnerability in the "Email Subscribers & Newsletters" plugin 4.1.6 for WordPress allows an attacker to inject malicious JavaScript code through a publicly available subscription form using the esfpx_name wp-admin/admin-ajax.php POST parameter.
- Affected versions
-
Min -, max 4.1.7.
- Status
-
vulnerable