CVE-2019-19981: CSRF
Published Dec 26, 2019
·Updated
The WordPress plugin, Email Subscribers & Newsletters, before 4.2.3 had a flaw that allowed for CSRF to be exploited on all plugin settings.
Affected Software
1 affected component
Icegram Email Subscribers \& Newsletters Wordpress<4.2.3
Event History
Dec 26, 2019
CVE Published
via MITRE·02:26 AM
Data Sourced
via MITRE·02:26 AM
DescriptionSeverity
Frequently Asked Questions
1
What is the vulnerability ID for this WordPress plugin?
The vulnerability ID for this WordPress plugin is CVE-2019-19981.
2
What is the severity of CVE-2019-19981?
The severity of CVE-2019-19981 is medium, with a severity value of 5.4.
3
What is the affected software for CVE-2019-19981?
The affected software for CVE-2019-19981 is the WordPress plugin Email Subscribers & Newsletters before version 4.2.3.
4
What is the CWE number associated with CVE-2019-19981?
The CWE number associated with CVE-2019-19981 is CWE-352.
5
How do I fix the vulnerability CVE-2019-19981?
To fix the vulnerability CVE-2019-19981, update the Email Subscribers & Newsletters plugin to version 4.2.3 or higher.