CVE-2019-19982: Medium severity icegram email subscribers & newsletters vulnerability
The WordPress plugin, Email Subscribers & Newsletters, before 4.2.3 had a flaw that allowed for unauthenticated option creation. In order to exploit this vulnerability, an attacker would need to send a /wp-admin/admin-post.php?esskip=1&optionname= request.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2019-19982?
CVE-2019-19982 is a vulnerability found in the WordPress plugin Email Subscribers & Newsletters before version 4.2.3.
How does the CVE-2019-19982 vulnerability work?
The CVE-2019-19982 vulnerability in the Email Subscribers & Newsletters plugin allows for unauthenticated option creation by sending a specific request.
What is the severity of CVE-2019-19982?
CVE-2019-19982 has a severity rating of medium with a CVSS score of 5.3.
How can I fix the CVE-2019-19982 vulnerability?
To fix the CVE-2019-19982 vulnerability, update the Email Subscribers & Newsletters plugin to version 4.2.3 or higher.
Where can I find more information about CVE-2019-19982?
You can find more information about CVE-2019-19982 at WPScan Vulnerability Database (https://wpvulndb.com/vulnerabilities/9946) and Wordfence Blog (https://www.wordfence.com/blog/2019/11/multiple-vulnerabilities-patched-in-email-subscribers-newsletters-plugin/).