CVE-2019-19985: Medium severity icegram email subscribers & newsletters vulnerability
Published Dec 26, 2019
·Updated
The WordPress plugin, Email Subscribers & Newsletters, before 4.2.3 had a flaw that allowed unauthenticated file download with user information disclosure.
Affected Software
1 affected component
Icegram Email Subscribers \& Newsletters Wordpress<4.2.3
Event History
Dec 26, 2019
CVE Published
via MITRE·02:25 AM
Data Sourced
via MITRE·02:25 AM
DescriptionSeverity
Frequently Asked Questions
1
What is the severity of CVE-2019-19985?
The severity of CVE-2019-19985 is medium.
2
What is the impact of CVE-2019-19985?
CVE-2019-19985 allows unauthenticated file download with user information disclosure.
3
Which software is affected by CVE-2019-19985?
The Email Subscribers & Newsletters plugin version up to 4.2.3 for WordPress is affected by CVE-2019-19985.
4
How can CVE-2019-19985 be exploited?
CVE-2019-19985 can be exploited by an unauthenticated attacker to download files and disclose user information.
5
Is there a patch available for CVE-2019-19985?
Yes, a patch is available to fix CVE-2019-19985. It is recommended to update to version 4.2.3 or higher of the Email Subscribers & Newsletters plugin.