Email Subscribers & Newsletters Plugin for WordPress < 4.5.6 Email Forgery/Spoofing Vulnerability

medium Web Application Scanning Plugin ID 112600

Synopsis

Email Subscribers & Newsletters Plugin for WordPress < 4.5.6 Email Forgery/Spoofing Vulnerability

Description

The WordPress Email Subscribers & Newsletters Plugin installed on the remote host is affected by an email forgery/spoofing vulnerability in the class-es-newsletters.php class due to missing authentication for a critical function. An unauthenticated, remote attacker can exploit this via a specially crafted ajax request, to send forged email to all recipients from the available lists of contacts or subscribers, with complete control over the content and subject of the email.

Note that the scanner has not tested for these issues but has instead relied only on the application's self-reported version number.

Solution

Upgrade to Email Subscribers & Newsletters Plugin for WordPress 4.5.6 or latest.

See Also

https://www.tenable.com/security/research/tra-2020-53

https://wordpress.org/plugins/email-subscribers/

Plugin Details

Severity: Medium

ID: 112600

Type: remote

Published: 9/23/2020

Updated: 4/16/2021

Scan Template: api, scan, pci

Risk Information

Risk Factor: Medium

CVSS v2.0

Base Score: 5

Vector: AV:N/AC:L/Au:N/C:N/I:P/A:N

CVSS v3.0

Base Score: 5.3

Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N

Vulnerability Information

CPE: cpe:2.3:a:icegram:email_subscribers_\&_newsletters:*:*:*:*:*:wordpress:*:*

Patch Publication Date: 9/10/2020

Vulnerability Publication Date: 9/10/2020

Reference Information

CVE: CVE-2020-5780