CVE-2019-20361: SQL Injection
There was a flaw in the WordPress plugin, Email Subscribers & Newsletters before 4.3.1, that allowed SQL statements to be passed to the database in the hash parameter (a blind SQL injection vulnerability).
Affected Software
Event History
Frequently Asked Questions
What is CVE-2019-20361?
CVE-2019-20361 is a blind SQL injection vulnerability found in the WordPress plugin Email Subscribers & Newsletters before version 4.3.1.
How severe is CVE-2019-20361?
CVE-2019-20361 is considered to be critical, with a severity value of 9.8.
What software is affected by CVE-2019-20361?
The Icegram Email Subscribers & Newsletters version up to 4.3.1 is affected by CVE-2019-20361.
How can I fix CVE-2019-20361?
To fix CVE-2019-20361, make sure to update the Email Subscribers & Newsletters plugin to version 4.3.1 or higher.
Are there any references for CVE-2019-20361?
Yes, you can find more information about CVE-2019-20361 at the following references: [1] http://packetstormsecurity.com/files/158568/WordPress-Email-Subscribers-And-Newsletters-4.2.2-SQL-Injection.html [2] https://wpvulndb.com/vulnerabilities/9947 [3] https://www.wordfence.com/blog/2019/11/multiple-vulnerabilities-patched-in-email-subscribers-newsletters-plugin/