cleantalk
Vulnerabilities and Security Researches

Icegram Express – Email Marketing, Newsletters and Automation for WordPress & WooCommerce, CVE-2020-5767

CVE, Research URL

CVE-2020-5767

Published on
Jul 18, 2020
Research Description
Cross-site request forgery in Icegram Email Subscribers & Newsletters Plugin for WordPress v4.4.8 allows a remote attacker to send forged emails by tricking legitimate users into clicking a crafted link.
Affected versions
Min -, max 4.5.1.
Status
vulnerable