cleantalk
Vulnerabilities and Security Researches

Icegram Express – Email Marketing, Newsletters and Automation for WordPress & WooCommerce, CVE-2019-19980

CVE, Research URL

CVE-2019-19980

Published on
Dec 26, 2019
Research Description
The WordPress plugin, Email Subscribers & Newsletters, before 4.2.3 had a privilege bypass flaw that allowed authenticated users (Subscriber or greater access) to send test emails from the administrative dashboard on behalf of an administrator. This occurs because the plugin registers a wp_ajax function to send_test_email.
Affected versions
Min -, max 4.2.3.
Status
vulnerable