CVE-2018-6015: Infoleak
An issue was discovered in the "Email Subscribers & Newsletters" plugin before 3.4.8 for WordPress. Sending an HTTP POST request to a URI with /?es=export at the end, and adding option=viewallsubscribers in the body, allows downloading of a CSV data file with all subscriber data.
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID?
The vulnerability ID is CVE-2018-6015.
What is the severity of CVE-2018-6015?
The severity of CVE-2018-6015 is high with a severity value of 7.5.
What is the affected software for CVE-2018-6015?
The affected software for CVE-2018-6015 is the Email Subscribers & Newsletters plugin before version 3.4.8 for WordPress.
How can an attacker exploit CVE-2018-6015?
An attacker can exploit CVE-2018-6015 by sending an HTTP POST request to a specific URI and adding certain parameters to download a CSV data file with all subscriber data.
Is there a fix available for CVE-2018-6015?
Yes, a fix is available for CVE-2018-6015 through the update to version 3.4.8 of the Email Subscribers & Newsletters plugin for WordPress.