CVE-2020-5767: CSRF
Published Jul 17, 2020
·Updated
Cross-site request forgery in Icegram Email Subscribers & Newsletters Plugin for WordPress v4.4.8 allows a remote attacker to send forged emails by tricking legitimate users into clicking a crafted link.
Affected Software
1 affected component
Icegram Email Subscribers \& Newsletters Wordpress=4.4.8
Event History
Jul 17, 2020
CVE Published
via MITRE·09:22 PM
Data Sourced
via MITRE·09:22 PM
DescriptionWeakness
Frequently Asked Questions
1
What is the vulnerability ID of the Cross-site request forgery in Icegram Email Subscribers & Newsletters Plugin for WordPress?
The vulnerability ID is CVE-2020-5767.
2
What is the severity of CVE-2020-5767?
The severity of CVE-2020-5767 is medium with a CVSS score of 6.5.
3
How does the Cross-site request forgery vulnerability in Icegram Email Subscribers & Newsletters Plugin for WordPress work?
The vulnerability allows a remote attacker to send forged emails by tricking legitimate users into clicking a crafted link.
4
What software versions are affected by CVE-2020-5767?
The affected software version is Icegram Email Subscribers & Newsletters Plugin for WordPress v4.4.8.
5
Is there a fix available for CVE-2020-5767?
Please refer to the official vendor's website or contact their support for a fix or patch.