Email Subscribers & Newsletters <= 3.4.7 - Unauthenticated Subscriber Download

2018-01-24 00:00
Dominykas Gelucevicius

Vulnerability Overview

An issue was discovered in the "Email Subscribers & Newsletters" plugin before 3.4.8 for WordPress. Sending an HTTP POST request to a URI with /?es=export at the end, and adding option=view_all_subscribers in the body, allows downloading of a CSV data file with all subscriber data.

Technical Analysis

REMEDIATION: Update to version 3.4.8, or a newer patched version --- IDENTIFIER: CWE-200 (Exposure of Sensitive Information to an Unauthorized Actor) The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.

External References

Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C