Email Subscribers & Newsletters Plugin for WordPress < 4.5.6 Email Forgery/Spoofing Vulnerability

medium Web App Scanning Plugin ID 112600

Synopsis

Email Subscribers & Newsletters Plugin for WordPress < 4.5.6 Email Forgery/Spoofing Vulnerability

Description

The WordPress Email Subscribers & Newsletters Plugin installed on the remote host is affected by an email forgery/spoofing vulnerability in the class-es-newsletters.php class due to missing authentication for a critical function. An unauthenticated, remote attacker can exploit this via a specially crafted ajax request, to send forged email to all recipients from the available lists of contacts or subscribers, with complete control over the content and subject of the email.

Note that the scanner has not tested for these issues but has instead relied only on the application's self-reported version number.

Solution

Upgrade to Email Subscribers & Newsletters Plugin for WordPress 4.5.6 or latest.

See Also

https://wordpress.org/plugins/email-subscribers/

https://www.tenable.com/security/research/tra-2020-53

Plugin Details

Severity: Medium

ID: 112600

Type: remote

Published: 9/23/2020

Updated: 3/14/2023

Scan Template: basic, full, pci, scan

Risk Information

VPR

Risk Factor: Low

Score: 2.2

CVSS v2

Risk Factor: Medium

Base Score: 5

Vector: CVSS2#AV:N/AC:L/Au:N/C:N/I:P/A:N

CVSS Score Source: CVE-2020-5780

CVSS v3

Risk Factor: Medium

Base Score: 5.3

Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N

CVSS Score Source: CVE-2020-5780

Vulnerability Information

CPE: cpe:2.3:a:icegram:email_subscribers_\&_newsletters:*:*:*:*:*:wordpress:*:*

Exploit Available: true

Exploit Ease: Exploits are available

Patch Publication Date: 9/10/2020

Vulnerability Publication Date: 9/10/2020

Reference Information

CVE: CVE-2020-5780