Email Subscribers & Newsletters <= 3.4.7 - Unauthenticated Subscriber Download
Strategic Overview
- Status
- Patched in 3.4.8
- Affected Plugin
- Email Subscribers & Newsletters – Email Marketing, Post Notifications & Newsletter Plugin for WordPress
- Affected Version
<= 3.4.7- CVSS
- 7.5High
- Weakness type
- CWE-200 · Exposure of Sensitive Information to an Unauthorized Actor
- CVE
CVE-2018-6015
At a glance
CVE-2018-6015 is a high-severity Exposure of Sensitive Information to an Unauthorized Actor vulnerability in the Email Subscribers & Newsletters WordPress plugin, affecting versions <= 3.4.7. It carries a CVSS score of 7.5 (reachable over the network; low attack complexity; high confidentiality impact). Exploitation requires no authentication. The issue is fixed in version 3.4.8; sites on affected versions should update now. Disclosed January 2018, reported by Dominykas Gelucevicius.
Vulnerability Overview
An issue was discovered in the "Email Subscribers & Newsletters" plugin before 3.4.8 for WordPress. Sending an HTTP POST request to a URI with /?es=export at the end, and adding option=view_all_subscribers in the body, allows downloading of a CSV data file with all subscriber data.
Technical Analysis
The vector marks this flaw as remotely reachable over the network, with low attack complexity — no special timing or configuration is needed, and no privileges on the target site, and no interaction from a victim user. A successful exploit has high impact on confidentiality.
CWE-200: Exposure of Sensitive Information to an Unauthorized Actor
Reaching this weakness in Email Subscribers & Newsletters <= 3.4.7 takes no account at all. Sensitive information exposure means data the application intended to keep internal is returned to a caller who should not be able to see it.
The disclosed data — credentials, tokens, customer records or internal paths — is usually worth more as material for a follow-up attack than as an end in itself. For Email Subscribers & Newsletters the fix is 3.4.8: builds <= 3.4.7 are affected, anything from 3.4.8 onward is not.
Remediation
Update to version 3.4.8, or a newer patched version
How does WordSec protect against this?
This one needs no account at all, which puts it outside what login hardening can reach; WordSec's login security narrows the account-level paths around it, and the firewall is what inspects the request itself. None of that substitutes for the fix: Email Subscribers & Newsletters 3.4.8 closes this, and updating the plugin is the step that ends it.
- Login Security
- Alerts
External References
Related records
Other vulnerabilities in Email Subscribers & Newsletters – Email Marketing, Post Notifications & Newsletter Plugin for WordPress
- 9.8CVE-2024-6172: Email Subscribers by Icegram Express SQL Injection
CVE-2024-6172 - 9.8CVE-2024-5756: Icegram Express - Email Subscribers SQL Injection
CVE-2024-5756 - 9.8CVE-2024-4295: Email Subscribers by Icegram Express SQL Injection
CVE-2024-4295 - 9.8CVE-2024-2876: Icegram Express - Email Subscribers SQL Injection
CVE-2024-2876 - 9.8CVE-2019-13569: Email Subscribers & Newsletters <= 4.1.7 SQL Injection
CVE-2019-13569 - 9.1CVE-2023-5414: Icegram Express Directory Traversal
CVE-2023-5414 - 8.8CVE-2024-4845: Icegram Express <= 5.7.22 SQL Injection Vulnerability
CVE-2024-4845 - 8.8CVE-2024-4010: Email Subscribers… Missing Authorization
CVE-2024-4010
Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C