CVE-2019-19984: Medium severity icegram email subscribers & newsletters vulnerability
Published Dec 26, 2019
·Updated
The WordPress plugin, Email Subscribers & Newsletters, before 4.2.3 had a flaw that allowed users with editpost capabilities to manage plugin settings and email campaigns.
Affected Software
1 affected component
Icegram Email Subscribers \& Newsletters Wordpress<4.2.3
Event History
Dec 26, 2019
CVE Published
via MITRE·02:25 AM
Data Sourced
via MITRE·02:25 AM
DescriptionSeverity
Frequently Asked Questions
1
What is the vulnerability ID of this issue?
The vulnerability ID of this issue is CVE-2019-19984.
2
What is the severity level of CVE-2019-19984?
CVE-2019-19984 has a severity level of medium (6.3).
3
What is affected by CVE-2019-19984?
The WordPress plugin Email Subscribers & Newsletters before version 4.2.3 is affected by CVE-2019-19984.
4
Who can exploit this vulnerability?
Users with edit_post capabilities can exploit the vulnerability.
5
How can the vulnerability be fixed?
To fix CVE-2019-19984, update the Email Subscribers & Newsletters plugin to version 4.2.3 or later.