CVE-2019-14364: XSS
An XSS vulnerability in the "Email Subscribers & Newsletters" plugin 4.1.6 for WordPress allows an attacker to inject malicious JavaScript code through a publicly available subscription form using the esfpxname wp-admin/admin-ajax.php POST parameter.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2019-14364?
CVE-2019-14364 is an XSS vulnerability in the Email Subscribers & Newsletters plugin 4.1.6 for WordPress.
How does CVE-2019-14364 work?
CVE-2019-14364 allows an attacker to inject malicious JavaScript code through a publicly available subscription form using the esfpx_name wp-admin/admin-ajax.php POST parameter.
What is the severity of CVE-2019-14364?
The severity of CVE-2019-14364 is medium with a severity value of 6.1.
How can I fix CVE-2019-14364?
To fix CVE-2019-14364, update to the latest version of the Email Subscribers & Newsletters plugin and apply any available patches or security updates.
Where can I find more information about CVE-2019-14364?
You can find more information about CVE-2019-14364 on GitHub, the WordPress plugin page, and WPScan Vulnerability Database.